This is a section for all my blogs.
Sha1‑Hulud Second Wave — Executive Summary and Immediate Risk
What happened: A new wave of Sha1‑Hulud supply‑chain attacks trojanized hundreds of npm packages (uploaded Nov 21–23, 2025) to run malicious code during the preinstall […]