News Radar RSS

Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp

Snyk Blog Cybersecurity Score 7/10

Summary

A new npm worm is abusing binding.gyp to trigger node-gyp during install, letting malicious packages run code without lifecycle scripts. It steals credentials, persists in GitHub, and self-propagates across maintainers.

SecurityDeveloper Tools

News Radar provides aggregated summaries. Full content and copyright remain with the original publisher.