Application Security
Shai-Hulud Is Now Generating Valid Sigstore Provenance Badges for Its Malicious npm Packages
Mini Shai-Hulud pushed ~42 malicious packages through a compromised @antv maintainer account on May 19 with valid Sigstore Fulcio certificates and Rekor entries. The green "verified" badge defenders have been trusting now sits on malicious code.