Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp
Summary
A new npm worm is abusing binding.gyp to trigger node-gyp during install, letting malicious packages run code without lifecycle scripts. It steals credentials, persists in GitHub, and self-propagates across maintainers.
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.