‘PackageGate’ Vulnerabilities Can Let Attackers Bypass Shai-Hulud Defenses

30/01/2026 DevOps DevOps.com
In the wake of the massive Shai-Hulud supply chain attack that ripped through npm late last year and compromised more than 700 packages and exposed 25,000 repositories, developers in the JavaScript world embraced a two-part defense strategy. The widely adopted playbook called for disabling lifecycle scripts and using lockfiles. “It became the standard advice everywhere […]