DEV Community

Discussion on: Mini Shai-Hulud: A persistent supply-chain worm

Collapse
 
gimi5555 profile image
Gilder Miller

Honestly pretty unsettling! Especially because it shows how much attackers are now adapting specifically to modern CI workflows and trusted publishing setups. The scale of it also makes it feel less like isolated package compromises and more like a very organized campaign. Really appreciate how clearly you broke everything down. Do you think teams are currently underestimating how exposed their CI environments actually are?