Bun - Tool

Threat entity extracted from intelligence sources

Frequency
23
occurrences
First Seen
November 24, 2025
Last Seen
August 6, 2026

Related Threat Clusters

  • Bitwarden CLI Compromised in Supply Chain Attack via npm

    A malicious version of the Bitwarden CLI password manager was distributed via npm, affecting version 2026.4.0 for a brief window on April 22, 2026. The attack exploited a compromised GitHub Action in Bitwarden's CI/CD…

    18 articles · Updated April 24, 2026
  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    753 articles · Updated April 29, 2026
  • NWHStealer Malware Campaign Evolves with Bun Loader and Anti-VM Techniques

    The NWHStealer infostealer has adopted a new distribution method utilizing the Bun JavaScript runtime, enhancing its delivery infrastructure. This Rust-based malware targets Windows systems, leveraging Bun's performance…

    2 articles · Updated May 8, 2026
  • Over 400 npm Packages Infected by Credential-Stealing Worm

    A self-replicating worm, identified as a variant of Mini Shai-Hulud, has compromised over 400 npm packages from various unrelated publishers. The malware is designed to steal developer credentials and propagate itself…

    2 articles · Updated August 6, 2026
  • Shai Hulud npm Worm Compromises Over 26,000 Repositories

    The Shai Hulud worm has compromised more than 26,000 public repositories in a supply chain attack. The attack targeted various npm packages, exploiting vulnerabilities that allowed unauthorized access to these…

    32 articles · Updated November 24, 2025
  • Claude Code Source Code Leaked via npm Packaging Error

    On March 31, 2026, Anthropic inadvertently exposed the entire source code of its AI tool, Claude Code, by including a 59.8 MB source map file in a public npm package. This leak, caused by human error, allowed access to…

    32 articles · Updated March 31, 2026
  • GitHub Actions Enhances Security Against 'Pwn Request' Attacks

    GitHub has released actions/checkout v7 to mitigate vulnerabilities associated with the pull_request_target workflow trigger, which has been exploited in 'pwn request' attacks. This update, announced on June 18, 2026,…

    9 articles · Updated June 22, 2026
  • Axios CVE-2026-40175: Critical Vulnerability Misrepresented as Easily Exploitable

    A critical vulnerability in Axios, tracked as CVE-2026-40175, was reported with a CVSS score of 9.9, suggesting potential for remote code execution (RCE) and cloud infrastructure compromise. However, analysis reveals…

    6 articles · Updated April 14, 2026
  • Shai-Hulud Malware Compromises 25K GitHub Repositories via npm Packages

    The Shai-Hulud malware has re-emerged, infecting over 500 trojanized npm packages and compromising secrets from more than 25,000 developers within three days. The malicious packages, including those from popular…

    4 articles · Updated November 24, 2025
  • PackageGate Vulnerabilities Affect Major JavaScript Package Managers

    Koi researchers identified a set of vulnerabilities known as 'PackageGate' in NPM, PNPM, VLT, and Bun. These flaws allow attackers to bypass supply chain protections and execute malicious code, posing risks to users of…

    2 articles · Updated January 28, 2026

Recent Intelligence Reports

  • Keyv And Cacheable Compromise — socket.dev · August 6, 2026
  • Gusano autopropagable infectó más de 400 paquetes npm y robó credenciales de desarrolladores — Ciberseguridadlatam · August 6, 2026
  • Miasma Malware Uses binding.gyp and Bun to Execute Hidden Payloads in npm Packages — Cybersecuritynews · June 26, 2026
  • Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets — Aikido.Dev · June 24, 2026
  • New PyPI Wave in Mini Shai-Hulud, Miasma, and Hades Campaign — Technadu · June 9, 2026
  • Meet Hades: The malware that lies to AI security agents — Csoonline · June 9, 2026
  • Shai-Hulud "Hades" Wave Hits Six PyPI Bioinformatics Packages via Stolen Tokens — Endorlabs · June 8, 2026
  • Endor Labs — www.endorlabs.com · June 4, 2026

CVSS v3.1 Breakdown