
When the Sandworm Came for My Secrets: Lessons from Shai-Hulud 2.0
How a sophisticated npm supply chain attack via a trojanized kill-port package compromised my development environment, exposing API keys to attacker-controlled repositories - and what I'm doing differently now.



