🕵️ THREAT RESEARCH & DEEP DIVES
- The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) — Palo Alto Unit 42
Unit 42 provides an updated, in-depth analysis of the evolving npm supply chain threat landscape post-Shai Hulud incident. Key findings include the emergence of wormable malware capable of lateral movement, novel CI/CD pipeline persistence techniques, and complex multi-stage attack chains targeting JavaScript ecosystems. The report highlights actionable mitigations for securing npm dependencies and build environments against these advanced supply chain threats.