EN / ES / HU
cybersecurity

Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp

Source: snyk.io 1 min read

Share

Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp

You are reading a summary. The full content is hosted on snyk.io.

A new npm worm is abusing binding.gyp to trigger node-gyp during install, letting malicious packages run code without lifecycle scripts. It steals credentials, persists in GitHub, and self-propagates across maintainers.

Related Articles