Related Threat Clusters
-
Bitwarden CLI Compromised in Supply Chain Attack via npm
A malicious version of the Bitwarden CLI password manager was distributed via npm, affecting version 2026.4.0 for a brief window on April 22, 2026. The attack exploited a compromised GitHub Action in Bitwarden's CI/CD…
18 articles · Updated April 24, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
753 articles · Updated April 29, 2026 -
NWHStealer Malware Campaign Evolves with Bun Loader and Anti-VM Techniques
The NWHStealer infostealer has adopted a new distribution method utilizing the Bun JavaScript runtime, enhancing its delivery infrastructure. This Rust-based malware targets Windows systems, leveraging Bun's performance…
2 articles · Updated May 8, 2026 -
Over 400 npm Packages Infected by Credential-Stealing Worm
A self-replicating worm, identified as a variant of Mini Shai-Hulud, has compromised over 400 npm packages from various unrelated publishers. The malware is designed to steal developer credentials and propagate itself…
2 articles · Updated August 6, 2026 -
Shai Hulud npm Worm Compromises Over 26,000 Repositories
The Shai Hulud worm has compromised more than 26,000 public repositories in a supply chain attack. The attack targeted various npm packages, exploiting vulnerabilities that allowed unauthorized access to these…
32 articles · Updated November 24, 2025 -
Claude Code Source Code Leaked via npm Packaging Error
On March 31, 2026, Anthropic inadvertently exposed the entire source code of its AI tool, Claude Code, by including a 59.8 MB source map file in a public npm package. This leak, caused by human error, allowed access to…
32 articles · Updated March 31, 2026 -
GitHub Actions Enhances Security Against 'Pwn Request' Attacks
GitHub has released actions/checkout v7 to mitigate vulnerabilities associated with the pull_request_target workflow trigger, which has been exploited in 'pwn request' attacks. This update, announced on June 18, 2026,…
9 articles · Updated June 22, 2026 -
Axios CVE-2026-40175: Critical Vulnerability Misrepresented as Easily Exploitable
A critical vulnerability in Axios, tracked as CVE-2026-40175, was reported with a CVSS score of 9.9, suggesting potential for remote code execution (RCE) and cloud infrastructure compromise. However, analysis reveals…
6 articles · Updated April 14, 2026 -
Shai-Hulud Malware Compromises 25K GitHub Repositories via npm Packages
The Shai-Hulud malware has re-emerged, infecting over 500 trojanized npm packages and compromising secrets from more than 25,000 developers within three days. The malicious packages, including those from popular…
4 articles · Updated November 24, 2025 -
PackageGate Vulnerabilities Affect Major JavaScript Package Managers
Koi researchers identified a set of vulnerabilities known as 'PackageGate' in NPM, PNPM, VLT, and Bun. These flaws allow attackers to bypass supply chain protections and execute malicious code, posing risks to users of…
2 articles · Updated January 28, 2026
Recent Intelligence Reports
- Keyv And Cacheable Compromise — socket.dev · August 6, 2026
- Gusano autopropagable infectó más de 400 paquetes npm y robó credenciales de desarrolladores — Ciberseguridadlatam · August 6, 2026
- Miasma Malware Uses binding.gyp and Bun to Execute Hidden Payloads in npm Packages — Cybersecuritynews · June 26, 2026
- Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets — Aikido.Dev · June 24, 2026
- New PyPI Wave in Mini Shai-Hulud, Miasma, and Hades Campaign — Technadu · June 9, 2026
- Meet Hades: The malware that lies to AI security agents — Csoonline · June 9, 2026
- Shai-Hulud "Hades" Wave Hits Six PyPI Bioinformatics Packages via Stolen Tokens — Endorlabs · June 8, 2026
- Endor Labs — www.endorlabs.com · June 4, 2026