Shai-Hulud Returns: Over 300 NPM Packages infected via Fake Bun Runtime Within Hours

60 points by bezdomni


ksynwa

My question is whether the javascript ecosystem is being targeted because of some innate weakness or it's just that it's the most popular and widely used language. There seem to be other factors too. Like this worm seems to be centred around GitHub Actions for propagation.