Menu

Post image 1
Post image 2
Post image 3
Post image 4
1 / 4
0

Mini Shai-Hulud: The Worm Returns and Goes Public

Reading 0:00
15s threshold

Affected Akamai Hunt customers have already received a detailed mapping of vulnerable assets with actionable segmentation and mitigation recommendations. Executive summary On May 11, 2026, a new wave of the Shai-Hulud supply chain campaign hit the npm ecosystem by publishing malicious versions of packages across the TanStack dependency tree. The attack was performed by hijacking legitimate release workflow through a continuous integration (CI) cache-poisoning attack and npm’s OpenID Connect (OIDC) publishing endpoint. The campaign quickly expanded beyond TanStack to additional npm packages linked to Mistral AI, UiPath, OpenSearch, and others. The next day, new GitHub repositories appeared to be hosting the source code of the malicious Shai-Hulud worm. In this blog post, we analyze the newly released malware, examine how this attack wave differs from earlier waves, and provide mitigation recommendations for maintainers and organizations.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More