Yarn — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
January 27, 2026
Last Seen
June 24, 2026

Yarn is a technology platform tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed January 27, 2026; most recent activity June 24, 2026.

Related Threat Clusters

  • Malicious JetBrains Plugins Exfiltrate AI API Keys from Developers

    A coordinated malware campaign has been uncovered involving at least 15 malicious plugins on the JetBrains Marketplace, designed to steal AI API keys from developers. These plugins, masquerading as AI coding assistants,…

    7 articles · Updated June 16, 2026
  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    697 articles · Updated April 29, 2026
  • GitHub Actions Enhances Security Against 'Pwn Request' Attacks

    GitHub has released actions/checkout v7 to mitigate vulnerabilities associated with the pull_request_target workflow trigger, which has been exploited in 'pwn request' attacks. This update, announced on June 18, 2026,…

    9 articles · Updated June 22, 2026

Recent Intelligence Reports

  • Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets — Aikido.Dev · June 24, 2026
  • Multiple JetBrains IDE plugins caught stealing AI keys — Aikido.Dev · June 16, 2026
  • Unplugged holes in the npm and yarn package managers could let attackers bypass defenses against Shai — Csoonline · January 27, 2026

CVSS v3.1 Breakdown