
GitHub closed two HackerOne reports from Deep Specter Research as ineligible, despite the Shai-Hulud supply-chain worm exploiting those design flaws. The worm has infected over 3,000 repositories and 200 developer accounts. Deep Specter found 516 malicious packages live across npm, PyPI, and RubyGems.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
400+ Arch Linux AUR Packages Hijacked for Credential Stealer