#shai-hulud”


GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Sep 26, 2026 // 17:36

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite […]

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Sep 25, 2026 // 17:47

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the […]

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

Sep 16, 2026 // 16:40

Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. […]

New Shai-Hulud attack trojanizes 19 science-focused PyPI packages

Jun 9, 2026 // 00:57

Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud supply-chain attack that delivered malware designed to steal […]

New Shai-Hulud malware wave compromises 600 npm packages

May 19, 2026 // 17:37

Threat actors earlier today published more than 600 malicious packages to the Node Package Manager (npm) index as part of a new Shai-Hulud supply-chain campaign. […]

Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account

May 19, 2026 // 09:36

Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of […]

Leaked Shai-Hulud malware fuels new npm infostealer campaign

May 18, 2026 // 20:36

The Shai-Hulud malware leaked last week is now used in new attacks on the Node Package Manager (npm) index, as infected packages emerged over the […]

Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages

May 12, 2026 // 11:52

TeamPCP,  the threat actor behind the recent supply chain attack spree, has been linked to the compromise of the npm and PyPI packages from TanStack, […]

SAP npm Packages Compromised by “Mini Shai-Hulud” Credential-Stealing Malware

Apr 29, 2026 // 19:32

Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to reports from Aikido […]