Sha1-Halud malware is back!
Looks like it’s back again. Over 600 affected npm packages but try not to panic.
Great information here form Snyk and also Git Guardian have shared some interesting IOCs that you can search for while you wait for your tooling to catch up!
https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/
https://blog.gitguardian.com/shai-hulud-2/

















































