GitHub pulls pin on npm's auto-run scripts

📰 The Register

Shai-Hulud worm exploited exactly this. Better late than never, says everyone except the malware authors

Published 10 Jun 2026
Read full article → ← Back to Reads