⤷ Title: The “Mini Shai-Hulud” Attack Hijacking SAP Developer Pipelines
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 15:04:51 +0000
════════════════════════
⌗ Tags: #Malware #@cap_js/sqlite #aws security #Azure #Bun runtime #CI/CD security #credential stealer #infosec #Kubernetes #mbt #Mini Shai_Hulud #npm malware #SAP #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 15:04:51 +0000
════════════════════════
⌗ Tags: #Malware #@cap_js/sqlite #aws security #Azure #Bun runtime #CI/CD security #credential stealer #infosec #Kubernetes #mbt #Mini Shai_Hulud #npm malware #SAP #supply chain attack
Daily CyberSecurity
The "Mini Shai-Hulud" Attack Hijacking SAP Developer Pipelines
SAP developers are under attack. A surgical credential stealer hijacks CI/CD runners and cloud tokens via npm preinstall hooks. Rotate all secrets immediately.
⤷ Title: The Worm Turns to PHP: Mini Shai-Hulud’s 20-Million-Install Hijack of Intercom
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 02:52:05 +0000
════════════════════════
⌗ Tags: #Malware #Bun runtime #Composer Exploit #cybersecurity #infosec #Intercom_PHP #Mini Shai_Hulud #Packagist #PHP Malware #Secret Theft #Socket #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 02:52:05 +0000
════════════════════════
⌗ Tags: #Malware #Bun runtime #Composer Exploit #cybersecurity #infosec #Intercom_PHP #Mini Shai_Hulud #Packagist #PHP Malware #Secret Theft #Socket #supply chain attack
Daily CyberSecurity
The Worm Turns to PHP: Mini Shai-Hulud’s 20-Million-Install Hijack of Intercom
Socket uncovers a massive Mini Shai-Hulud breach in the Intercom PHP SDK. Malicious version 5.0.2 steals cloud secrets and GitHub tokens. Rotate keys now!
⤷ Title: Desert Power in the Code: How the “Mini Shai-Hulud” Malware Burrows into SAP’s npm Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 07:44:09 +0000
════════════════════════
⌗ Tags: #Malware #@cap_js #CI/CD Security #CircleCI #cloud security #Credentials Theft #Cyber Security 2026 #GitHub Actions #malware #Mini Shai_Hulud #npm #SAP #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 07:44:09 +0000
════════════════════════
⌗ Tags: #Malware #@cap_js #CI/CD Security #CircleCI #cloud security #Credentials Theft #Cyber Security 2026 #GitHub Actions #malware #Mini Shai_Hulud #npm #SAP #supply chain attack
Information Security News
Desert Power in the Code: How the "Mini Shai-Hulud" Malware Burrows into SAP’s npm Supply Chain
Adversaries have once again targeted the npm supply chain, though this incursion pursued a surgical and perilous objective:
⤷ Title: TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 13 May 2026 15:18:47 +0000
════════════════════════
⌗ Tags: #Security #Malware #Cyber Attack #Mini Shai_Hulud #NPM #PyPI #Supply Chain #TeamPCP
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 13 May 2026 15:18:47 +0000
════════════════════════
⌗ Tags: #Security #Malware #Cyber Attack #Mini Shai_Hulud #NPM #PyPI #Supply Chain #TeamPCP
Hackread
TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages
TeamPCP hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.
⤷ Title: Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
Penetration Testing Tools
Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
The Mini Shai-Hulud incursion has once again laid siege to the software supply chain. While the initial offensive
⤷ Title: Shai-Hulud Returns: Massive npm Supply Chain Attack Hijacks AntV Ecosystem to Scrape GitHub Runner Memory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:52:05 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #atool #Claude Code Hijack #Cyber Security #GitHub Actions #infosec #Mini Shai_Hulud #npm Worm #Runner Memory Scraper #supply chain attack #timeago.js
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:52:05 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #atool #Claude Code Hijack #Cyber Security #GitHub Actions #infosec #Mini Shai_Hulud #npm Worm #Runner Memory Scraper #supply chain attack #timeago.js
Daily CyberSecurity
Shai-Hulud Returns: Massive npm Supply Chain Attack Hijacks AntV Ecosystem to Scrape GitHub Runner Memory
The Mini Shai-Hulud npm worm has hijacked the atool account, poisoning AntV & timeago.js to scrape GitHub runner memory. Execute a full reset now!
⤷ Title: The Missed Token: Grafana Labs Suffers Source Code Theft via Shai-Hulud npm Worm Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 04:06:15 +0000
════════════════════════
⌗ Tags: #Data Leak #Cyber Security #GitHub Token Rotation #Grafana Labs #Incident Response #infosec #Mini Shai_Hulud #npm Worm #Ransom Demand #Source Code Theft #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 04:06:15 +0000
════════════════════════
⌗ Tags: #Data Leak #Cyber Security #GitHub Token Rotation #Grafana Labs #Incident Response #infosec #Mini Shai_Hulud #npm Worm #Ransom Demand #Source Code Theft #supply chain attack
Daily CyberSecurity
The Missed Token: Grafana Labs Suffers Source Code Theft via Shai-Hulud npm Worm Campaign
Grafana Labs confirms a targeted cyberattack and source code theft after a missed token from the Mini Shai-Hulud npm worm left a repository exposed.
⤷ Title: Ecosystem Poisoned: Mini Shai-Hulud Worm Hijacks @antv npm Packages to Target CI/CD Pipelines
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 02:59:48 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #CI/CD Pipeline Security #Cyber Security #echarts_for_react #GitHub Actions Memory Scraping #infosec #Mini Shai_Hulud #npm Supply Chain Attack #Sigstore Forgery #TeamPCP #Token Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 02:59:48 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #CI/CD Pipeline Security #Cyber Security #echarts_for_react #GitHub Actions Memory Scraping #infosec #Mini Shai_Hulud #npm Supply Chain Attack #Sigstore Forgery #TeamPCP #Token Theft
Daily CyberSecurity
Ecosystem Poisoned: Mini Shai-Hulud Worm Hijacks @antv npm Packages to Target CI/CD Pipelines
Microsoft warns of an aggressive Mini Shai-Hulud worm attack targeting the @antv npm ecosystem and stealing secrets from cloud-connected CI/CD pipelines.
⤷ Title: The Shai-Hulud Infiltration: Red Hat Exploited in Sovereign Supply Chain Breach
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 04:35:11 +0000
════════════════════════
⌗ Tags: #Malware #credential harvesting malware #GitHub Actions OIDC bypass #Mini Shai_Hulud worm #Red Hat NPM attack #supply chain compromise #trusted publishing vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 04:35:11 +0000
════════════════════════
⌗ Tags: #Malware #credential harvesting malware #GitHub Actions OIDC bypass #Mini Shai_Hulud worm #Red Hat NPM attack #supply chain compromise #trusted publishing vulnerability
Daily CyberSecurity
The Shai-Hulud Infiltration: Red Hat Exploited in Sovereign Supply Chain Breach
Recently, several prominent cybersecurity corporations simultaneously intercepted a series of malicious software repositories. Specifically, an adversary uploaded these corrupted packages directly…
⤷ Title: How to Protect Yourself from npm Supply Chain Attacks
════════════════════════
𐀪 Author: Digvijay Bhakuni
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 09:11:00 GMT
════════════════════════
⌗ Tags: #typosquatting #nodejs #hacking #npm #mini_shai_hulud
════════════════════════
𐀪 Author: Digvijay Bhakuni
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 09:11:00 GMT
════════════════════════
⌗ Tags: #typosquatting #nodejs #hacking #npm #mini_shai_hulud
Medium
How to Protect Yourself from npm Supply Chain Attacks
The Growing Threat Hidden Behind npm install
⤷ Title: GEEKOM Mini PC Driver Downloads Found Bundled With Backdoor Since 2024
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 08:05:34 +0000
════════════════════════
⌗ Tags: #Malware #AMD #backdoor #Driver Malware #GEEKOM #Mini PC #supply chain attack #Website Compromise
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 08:05:34 +0000
════════════════════════
⌗ Tags: #Malware #AMD #backdoor #Driver Malware #GEEKOM #Mini PC #supply chain attack #Website Compromise
Daily CyberSecurity
GEEKOM Mini PC Driver Downloads Found Bundled With Backdoor Since 2024
Domestic mini PC manufacturer GEEKOM was recently discovered to be distributing driver downloads through its official website that contained a backdoor. A Reddit user first spotted the anomaly and…