Attackers stole a limited amount of internal credential material after malware hidden in poisoned packages reached two staff machines

Six-minute supply chain blitz pushed 84 malicious versions with credential theft and disk-wiping code

Hundreds of packages across npm and PyPI have been compromised in a new Shai-Hulud supply-chain campaign delivering credential-stealing malware targeting developers.