npm security

Shai-Hulud npm Worm Targets TanStack Ecosystem With Destructive Payload
A new Shai-Hulud npm worm variant targeted 42 TanStack packages with a payload that steals credentials and threatens to wipe user home directories if stolen tokens are revoked.

Bitwarden CLI npm Package Compromised to Steal Developer Credentials
Bitwarden CLI compromised in a major security incident affecting developer credentials. The attack affected developers relying on the command-line tool for password vault operations.
