🧵…nicht nur das oben erwähnte AntV Code war eine GitHub Attake, sondern GitHub an sich:

«GitHub-Hack — Tausende interne Repositorys durch VS Code gestohlen:
Die Entwicklerplattform GitHub hat den Diebstahl von rund 3800 internen Repositorys bestätigt. Auslöser war eine schädliche Erweiterung für Visual Studio Code, die ein Mitarbeiter installierte und die Angreifern Zugriff auf interne Systeme verschaffte»

🧑‍💻 https://winfuture.de/news,158824.html

#github #hacking #itsicherheit #coding #minishaihulud #vscode

GitHub-Hack: Tausende interne Repositorys durch VS Code gestohlen

Die Entwicklerplattform GitHub hat den Diebstahl von rund 3800 internen Repositorys bestätigt. Auslöser war eine schädliche Erweiterung für Visual Studio Code, die ein Mitarbeiter installierte und die Angreifern Zugriff auf interne Systeme verschaffte.

WinFuture.de

Mini Shai-Hulud Worm Targets AntV Ecosystem with Coordinated npm Package Attack

In a shocking one-hour surge, 639 malicious versions were pushed across 323 unique npm packages, crippling the AntV ecosystem with a massive coordinated attack linked to the Mini Shai-Hulud worm. This brazen move was designed not only to spread chaos but also to slow down analysis and detection efforts.

https://osintsights.com/mini-shai-hulud-worm-targets-antv-ecosystem-with-coordinated-npm-package-attack?utm_source=mastodon&utm_medium=social

#MiniShaihulud #NpmPackageAttack #AntvEcosystem #SupplyChain #EmergingThreats

Mini Shai-Hulud Worm Targets AntV Ecosystem with Coordinated npm Package Attack

Learn how the Mini Shai-Hulud worm launched a massive npm package attack on the AntV ecosystem and find out how to protect your project from similar threats now.

OSINTSights

«Hunderte bösartige npm-Pakete im AntV-Ökosystem entdeckt:
Das Datenvisualisierungs-Ökosystem AntV war Ziel einer Mini-Shai-Hulud-Lieferkettenattacke mit Hunderten schädlicher npm-Pakete.»

Schon wieder viele npm-Pakete. Liegt das an npm selber oder ist dies im allgemeinen ein Code-Struktur-Fehler? Betreffen tut es schlussendlich alle User dieser Software, auch wenn die es "nur" nutzen.

🧑‍💻 https://www.heise.de/news/Hunderte-boesartige-npm-Pakete-im-AntV-Oekosystem-entdeckt-11300242.html

#npm #minishaihulud #itsicherheit #js #ts #javascript #typescript #webdev #antv

Hunderte bösartige npm-Pakete im AntV-Ökosystem entdeckt

Das Datenvisualisierungs-Ökosystem AntV war Ziel einer Mini-Shai-Hulud-Lieferkettenattacke mit Hunderten schädlicher npm-Pakete.

heise online

Malware Campaign Compromises Hundreds of npm Packages

A new, highly aggressive malware campaign, linked to the notorious TeamPCP group, has infected hundreds of npm packages, putting countless environments at risk of exposure. If you're concerned about potential damage, take immediate action to rotate secrets, remove persistence artifacts, and review recent publish activity.

https://osintsights.com/malware-campaign-compromises-hundreds-of-npm-packages?utm_source=mastodon&utm_medium=social

#MalwareOperations #Npm #Teampcp #MiniShaihulud #SupplyChain

Malware Campaign Compromises Hundreds of npm Packages

Protect your environment from TeamPCP's Mini Shai‑Hulud malware campaign compromising hundreds of npm packages - learn how to secure your system now and prevent further attacks.

OSINTSights
🐍 Beware the mighty "Mini Shai-Hulud," devouring npm packages like a snack! 🍿 Apparently, "314" is the new "317," but who’s counting in the world of open-source chaos? 🤷‍♂️ Just another day in the life of developers pretending they can control the uncontrollable. 🙃
https://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/ #MiniShaiHulud #npmChaos #openSourceDev #packageManagement #developerLife #HackerNews #ngated
Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised

A compromised npm maintainer account published 637 malicious versions across 317 packages including size-sensor, echarts-for-react, timeago.js, and hundreds of @antv scoped packages, affecting 15M+ monthly downloads.

SafeDep - Real-time Open Source Software Supply Chain Security
Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised

A compromised npm maintainer account published 637 malicious versions across 317 packages including size-sensor, echarts-for-react, timeago.js, and hundreds of @antv scoped packages, affecting 15M+ monthly downloads.

SafeDep - Real-time Open Source Software Supply Chain Security

https://winbuzzer.com/2026/05/15/openai-confirms-security-breach-in-tanstack-supply-xcxwbn/

OpenAI confirmed that a poisoned open-source package breached employee devices and let attackers steal credentials from a limited set of its internal source code repositories.

#AI #OpenAI #Cybersecurity #Malware #DataBreaches #TanStack #MiniShaiHulud #npm

J’avoue, le mini shai hulud, c’est beau.
https://youtu.be/gwTQLZSIlsU
#npm #minishaihulud
A single PR just hijacked the NPM registry...

YouTube
Supply-Chain-Angriff auf TanStack: 42 Pakete kompromittiert

Zahlreiche TanStack-Pakete auf npm haben eine Supply-Chain-Attacke erlitten, offenbar im Rahmen der Angriffswelle „Mini Shai-Hulud“.

heise online

📢⚠️ A #TeamPCP-linked account claims to be selling alleged internal Mistral AI repositories days after the Mini Shai-Hulud supply chain attacks targeted npm and PyPI packages linked to the AI company.

Read: https://hackread.com/teampcp-mistral-ai-repositories-mini-shai-hulud-attack/

#CyberSecurity #MistralAI #MiniShaiHulud #DataBreach

TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack

TeamPCP claims to be selling alleged Mistral AI repositories on a hacker forum after the Mini Shai-Hulud attack targeted npm and PyPI ecosystems.

Hackread - Cybersecurity News, Data Breaches, AI and More