Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp
Summary
A new npm worm is abusing binding.gyp to trigger node-gyp during install, letting malicious packages run code without lifecycle scripts. It steals credentials, persists in GitHub, and self-propagates across maintainers.
News Radar provides aggregated summaries. Full content and copyright remain with the original publisher.