Security researchers have uncovered another supply chain attack targeting developers: 19 typosquatting npm packages published on npmjs.com that steal credentials, infect projects, and propagate themselves across developer environments. The operation, dubbed âSANDWORM_MODE,â represents a (still) rare example of worm-like malware designed to spread through software supply chains rather than traditional end-user systems. New npm worm builds on Shai-Huludâs playbook After last yearâs bombshell appearance of the self-replicating âShai-Huludâ worm on the official npm registry, the ⌠More â The post Self-spreading npm malware targets developers in new supply chain attack appeared first on Help Net Security .