Bun Runtime - Tool

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
November 24, 2025
Last Seen
July 8, 2026

Related Threat Clusters

  • Bitwarden CLI Compromised in Supply Chain Attack via npm

    A malicious version of the Bitwarden CLI password manager was distributed via npm, affecting version 2026.4.0 for a brief window on April 22, 2026. The attack exploited a compromised GitHub Action in Bitwarden's CI/CD…

    18 articles · Updated April 24, 2026
  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    737 articles · Updated April 29, 2026
  • TeamPCP Targets CI/CD Pipelines to Steal Developer Credentials

    TeamPCP, a financially motivated threat actor, has been conducting a campaign targeting software supply chains from March 19 to April 24, 2026. The group exploited trusted CI/CD and release workflows to steal sensitive…

    4 articles · Updated May 15, 2026
  • GitHub Breach Linked to Compromised Nx Console Extension

    On May 19, 2026, GitHub announced an investigation into unauthorized access to internal repositories after a malicious Visual Studio Code extension was executed on an employee's device. The attack, attributed to the…

    5 articles · Updated July 7, 2026
  • Shai Hulud npm Worm Compromises Over 26,000 Repositories

    The Shai Hulud worm has compromised more than 26,000 public repositories in a supply chain attack. The attack targeted various npm packages, exploiting vulnerabilities that allowed unauthorized access to these…

    32 articles · Updated November 24, 2025
  • Shai-Hulud Malware Infects npm Packages, Compromising Thousands of Repositories

    A new wave of the Shai-Hulud malware has compromised nearly 500 npm packages, affecting over 26,000 GitHub repositories. This self-replicating worm, which targets developers' credentials and secrets, has been linked to…

    43 articles · Updated November 29, 2025

Recent Intelligence Reports

  • Link — edge.prnewswire.com · July 8, 2026
  • Endor Labs — www.endorlabs.com · June 4, 2026
  • Analyzing TeamPCP's Supply Chain Attacks: Checkmarx KICS and elementary — Trendmicro · May 14, 2026
  • Password safe Bitwarden: Command-line client trojanized — Heise.De · April 23, 2026
  • Bitwarden CLI npm package compromised to steal developer credentials — Bleepingcomputer · April 23, 2026
  • FAQ About Sha1-Hulud 2.0: The "Second Coming" of the npm Supply — Tenable · November 24, 2025

CVSS v3.1 Breakdown