JavaScript Supply Chain Attack Threatens DeFi Ecosystem
        
        
        
        
          
        
        
      
        
    
        
        A compromised JavaScript package, widely integrated across DeFi, enables transaction hijacking, posing a systemic risk to user funds and operational integrity.
        
        NPM Supply Chain Compromised by Self-Replicating Shai-Hulud Token-Stealing Worm
        
        
        
        
          
        
        
      
        
    
        
        A novel self-replicating worm is actively compromising NPM developer accounts, injecting malicious code into popular packages to steal cloud service tokens and expose private repositories, posing systemic risk to software supply chains.
