Red-Hat-Infostealer kommt auf mehr als 100.000 Downloads

Die Managed Cloud Services von Red Hat waren das Ziel einer Lieferkettenattacke. Dahinter steckt ein Klon des npm-Wurms Mini Shai‑Hulud.

heise online
Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm

Multiple official @redhat-cloud-services npm packages were compromised with a credential-stealing worm derived from the open-sourced Mini Shai-Hulud malware, targeting cloud credentials, and developer tooling across CI/CD pipelines.

Hunderte bösartige npm-Pakete im AntV-Ökosystem entdeckt

Das Datenvisualisierungs-Ökosystem AntV war Ziel einer Mini-Shai-Hulud-Lieferkettenattacke mit Hunderten schädlicher npm-Pakete.

heise online

Mini Shai-Hulud Worm Targets AntV Ecosystem with Coordinated npm Package Attack

In a shocking one-hour surge, 639 malicious versions were pushed across 323 unique npm packages, crippling the AntV ecosystem with a massive coordinated attack linked to the Mini Shai-Hulud worm. This brazen move was designed not only to spread chaos but also to slow down analysis and detection efforts.

https://osintsights.com/mini-shai-hulud-worm-targets-antv-ecosystem-with-coordinated-npm-package-attack?utm_source=mastodon&utm_medium=social

#MiniShaihulud #NpmPackageAttack #AntvEcosystem #SupplyChain #EmergingThreats

Mini Shai-Hulud Worm Targets AntV Ecosystem with Coordinated npm Package Attack

Learn how the Mini Shai-Hulud worm launched a massive npm package attack on the AntV ecosystem and find out how to protect your project from similar threats now.

OSINTSights

Malware Campaign Compromises Hundreds of npm Packages

A new, highly aggressive malware campaign, linked to the notorious TeamPCP group, has infected hundreds of npm packages, putting countless environments at risk of exposure. If you're concerned about potential damage, take immediate action to rotate secrets, remove persistence artifacts, and review recent publish activity.

https://osintsights.com/malware-campaign-compromises-hundreds-of-npm-packages?utm_source=mastodon&utm_medium=social

#MalwareOperations #Npm #Teampcp #MiniShaihulud #SupplyChain

Malware Campaign Compromises Hundreds of npm Packages

Protect your environment from TeamPCP's Mini Shai‑Hulud malware campaign compromising hundreds of npm packages - learn how to secure your system now and prevent further attacks.

OSINTSights
🐍 Beware the mighty "Mini Shai-Hulud," devouring npm packages like a snack! 🍿 Apparently, "314" is the new "317," but who’s counting in the world of open-source chaos? 🤷‍♂️ Just another day in the life of developers pretending they can control the uncontrollable. 🙃
https://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/ #MiniShaiHulud #npmChaos #openSourceDev #packageManagement #developerLife #HackerNews #ngated
Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised

A compromised npm maintainer account published 637 malicious versions across 317 packages including size-sensor, echarts-for-react, timeago.js, and hundreds of @antv scoped packages, affecting 15M+ monthly downloads.

SafeDep - Real-time Open Source Software Supply Chain Security
Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised

A compromised npm maintainer account published 637 malicious versions across 317 packages including size-sensor, echarts-for-react, timeago.js, and hundreds of @antv scoped packages, affecting 15M+ monthly downloads.

SafeDep - Real-time Open Source Software Supply Chain Security

https://winbuzzer.com/2026/05/15/openai-confirms-security-breach-in-tanstack-supply-xcxwbn/

OpenAI confirmed that a poisoned open-source package breached employee devices and let attackers steal credentials from a limited set of its internal source code repositories.

#AI #OpenAI #Cybersecurity #Malware #DataBreaches #TanStack #MiniShaiHulud #npm

J’avoue, le mini shai hulud, c’est beau.
https://youtu.be/gwTQLZSIlsU
#npm #minishaihulud
A single PR just hijacked the NPM registry...

YouTube
Supply-Chain-Angriff auf TanStack: 42 Pakete kompromittiert

Zahlreiche TanStack-Pakete auf npm haben eine Supply-Chain-Attacke erlitten, offenbar im Rahmen der Angriffswelle „Mini Shai-Hulud“.

heise online