Lotu Radar About · RSS

Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp

Snyk Blog Cybersecurity Score 7/10

Summary

A new npm worm is abusing binding.gyp to trigger node-gyp during install, letting malicious packages run code without lifecycle scripts. It steals credentials, persists in GitHub, and self-propagates across maintainers.

Developer ToolsSecurity

Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.