
Shai-Hulud: Self‑Spreading npm Backdoor Hits tinycolor and 40+ Packages
A self-propagating npm attack backdoored @ctrl/tinycolor and 40+ packages to steal multi-cloud and GitHub secrets, persist via Actions workflows, and exfiltrate data—demanding immediate removal, credential rotation, and CI/CD hardening.






























