According to SlowMist monitoring, the npm worm named "Mini Shai-Hulud" spreads through projects such as TanStack and UiPath, hijacking GitHub credentials to publish malicious packages and steal CI/CD keys, cloud service credentials, and cryptocurrency wallet information. SlowMist recommends affected projects inspect the router_init.js file, rotate exposed credentials, and monitor for suspicious activity.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
