Skip to content

CVE-2026-45321

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
May 13, 2026
Last Seen
September 19, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into legitimate packages, which execute during installation to steal sensitive credential...

On May 22, 2026, threat actors exploited a compromised OAuth token from a former CrowdSec employee's machine to steal 170 private GitHub repositories. The breach was linked to the TanStack npm supply chain attack, where malicious npm packages were used to extract credentials. CrowdSec discovered the...

Public Exploits

Checking GitHub for proof-of-concept code…