EPISODE · Sep 18, 2025 · 24 MIN
Episode 02 | Worms in the NPM Supply Chain: Singularity, Phished Maintainers, and Shai-Hulud
from Ahl About Identity
Over just a few weeks, the NPM ecosystem was hit by three major security incidents: the Singularity campaign exploiting GitHub Actions for token theft, a phishing attack on a package maintainer, and Shai-Hulud, the first worm-like malware propagation in NPM. In this episode of The Permiso Podcast, our CTO Ian Ahl, breaks down how each event unfolded, the role of stolen credentials, and what these attacks mean for developers and security teams navigating modern supply chain risks.
NOW PLAYING
Episode 02 | Worms in the NPM Supply Chain: Singularity, Phished Maintainers, and Shai-Hulud
No transcript for this episode yet
Similar Episodes
Mar 26, 2026 ·1m
Mar 19, 2026 ·34m
Feb 18, 2026 ·11m
Feb 11, 2026 ·45m