home tags events about login
one honk maybe more

benjojo posted 24 Nov 2025 11:31 +0000

Shai-Hulud Returns: Over 300 NPM Packages infected via Fake Bun Runtime Within Hours

(link)

"No Way To Prevent This" Says Only Package Ecosystem Where This Regularly Happens

benjojo replied 24 Nov 2025 11:34 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/vl8hjtG8NZbcbZfPGD

I guess it's funny to laugh at the JS people, but it seems like the rust ecosystem is ripe for this kind of thing too...

Github's lack of care (it seems) to NPM (and general actions security etc) seems to be the main attrator to this, that and the wider usage (Plus instant deployment from git stuff) of the javascript ecosystem