shipfeedAI news, curated daily

23:56:25 CET
20 MAY23:56:25shipfeed
pull to refreshlast sync
Just in — 30 new
§ feed · storyline

Shai-Hulud 2.0 Supply Chain Compromise

Vercel confirms a supply chain attack via compromised npm packages added a stealthy loader to package.json files, with a limited set of customer builds affected and no Vercel-managed systems impacted.

Nov 24 · · primary fetch1 sourceupdated Nov 24 ·

Multiple npm packages from various web services through account takeover/developer compromise. A malicious actor was able to add a stealthy loader to the package.json file that locates the Bun runtime, silently installs, then executes a malicious script.were compromised Our investigation has shown that no Vercel environment was impacted and we are notifying a small set of customers with affected builds. Vercel has taken immediate steps to address this for our customers. As an initial step, we reset the cache for projects that pulled in any of the vulnerable packages while we continue to investigate whether any loaders successfully ran.

We will continue to issue updates throughout our investigation. Read more Impact to Vercel Customers As of this publication, or internal build processes have been impacted.no Vercel-managed systems identified referencing the compromised packages.Preliminary analysisa limited set of Vercel customer builds Impacted customers are being contacted directly with detailed mitigation steps.

read full article on vercel.com
§ sources1 publication · timeline below
  1. vercel.comShai-Hulud 2.0 Supply Chain Compromiseprimary