What's the big deal with this worming supply chain attack?
Well it seems that the attackers may have forced GitHub and NPM into inaction.
The worm is designed to take revenge on infected users if too many of the infected packages are taken off NPM or if GitHub takes down the stolen user data.
So in the mean time that means us developers and users will need to stop and remove the infection as quickly as possible ourselves to protect your systems.
https://about.gitlab.com/blog/gitlab-discovers-widespread-npm-supply-chain-attack/
If time is money and helping the community is good, then this almost completely broke and emotionally damaged open source nerd would dearly appreciate some donations so I can stay focused on helping untangle this worm.
Was planning to spend this week on a mad dash to get my latest apps shipped by turkey day(to you know, make money) but instead I'm doing worm mitigation 😭
https://ko-fi.com/nullagent
https://ko-fi.com/dataparty
#cybersecurity #incidentresponse #ShalHulud #WalkWithoutRhythm