The Shai-Hulud supply-chain malware campaign is exploiting the automated systems developers trust to publish software safely.

The Shai-Hulud malware leaked last week is now used in new attacks on the Node Package Manager (npm) index, as infected packages emerged over the weekend.

Plus three other stealers in three other packages, all from the same scumbag