#“mini


GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Sep 26, 2026 // 17:36

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite […]

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Sep 25, 2026 // 17:47

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the […]

Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account

May 19, 2026 // 09:36

Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of […]

Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages

May 12, 2026 // 11:52

TeamPCP,  the threat actor behind the recent supply chain attack spree, has been linked to the compromise of the npm and PyPI packages from TanStack, […]

Telegram Mini Apps abused for crypto scams, Android malware delivery

May 3, 2026 // 17:56

Cybersecurity researchers have uncovered a large-scale fraud operation that uses Telegram’s Mini App feature to run crypto scams, impersonate well-known brands, and distribute Android malware. […]

SAP npm Packages Compromised by “Mini Shai-Hulud” Credential-Stealing Malware

Apr 29, 2026 // 19:32

Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to reports from Aikido […]