OpenSearch - Tool

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
February 24, 2026
Last Seen
September 1, 2026

Related Threat Clusters

  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    753 articles · Updated April 29, 2026
  • GitHub Breach Linked to Compromised Nx Console Extension

    On May 19, 2026, GitHub announced an investigation into unauthorized access to internal repositories after a malicious Visual Studio Code extension was executed on an employee's device. The attack, attributed to the…

    5 articles · Updated July 7, 2026
  • OpenAI Faces Supply Chain Attack via TanStack npm Library

    OpenAI confirmed a security breach affecting two employee devices due to a supply chain attack linked to the TanStack npm library, part of a broader campaign called Mini Shai-Hulud. The attack involved the publication…

    39 articles · Updated May 14, 2026
  • AWS WAF Logs Exploited for Credential Harvesting

    A security researcher detailed the process of analyzing AWS WAF logs to extract credentials for unauthorized access. The researcher noted that AWS WAF captures extensive request data, including headers and IP addresses,…

    2 articles · Updated September 1, 2026
  • ASD Launches Azul Malware Analysis Tool for Enhanced Cyber Defense

    On February 24, 2026, the Australian Signals Directorate (ASD) released Azul, an open-source malware repository and analysis platform. Designed for enterprise and government security teams, Azul features a structured…

    5 articles · Updated February 24, 2026

Recent Intelligence Reports

  • WAFv2 Best Practices documentation — aws.github.io · September 1, 2026
  • Link — edge.prnewswire.com · July 8, 2026
  • The next big DeFi exploit will start before the code is deployed — Cryptorank · May 26, 2026
  • TeamPCP releases 'vibe coded' Shai-Hulud source code, issues challenge — Scworld · May 15, 2026
  • OpenAI confirms security breach in TanStack supply chain attack — Bleepingcomputer · May 14, 2026
  • OpenAI denies user data exposure from TanStack npm, Mini Shai — Cryptopolitan · May 14, 2026
  • OpenAI says no user data was touched in the TanStack npm worm — Thenextweb · May 14, 2026
  • Australia's Cyber Agency Releases Azul, an Open Source Malware Analysis Repository — Itsfoss · February 24, 2026

CVSS v3.1 Breakdown