SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

Part of the Shai Hulud Second Coming supply chain attack campaign. This malicious package was designed to steal credentials and exfiltrate sensitive data from developer environments.

vue-browserupdate-nuxt@1.0.5Malicious
Verified
Analysed at: 4/12/26, 5:30 AM
Source: -
SHA256:
Confidence: High