The Spice Must Flow
A new kind of software supply chain attack has arrived — one that can replicate itself. Meet Shai-Hulud, the first self-propagating worm in the npm ecosystem, turning trusted APIs into its weapon. This blog breaks down how it spread and how context-aware API security could have stopped it.