Mend.io Malicious Packages

Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - Mini Shai Hulud is Back 1

Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account

Mini Shai-Hulud strikes again: 323 npm packages compromised via @antv's atool.

Read More
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - Mend securing RubyGems

Inside the RubyGems Supply Chain Attack: How Mend Defender Caught a Coordinated Flood Before It Spread

How Mend.io caught a coordinated RubyGems attack and what it teaches us.

Read More
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - Mini Shai Hulud is Back

Mini Shai-Hulud Is Back: 172 npm and PyPI Packages Compromised in Latest Wave

Shai-Hulud's largest wave: 172 npm and PyPI packages compromised in 48 hours.

Read More
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - npm supply chain attack

PhantomRaven Wave 5: New Undocumented NPM Supply Chain Campaign Targets DeFi, Cloud, and AI Developers

33 malicious NPM packages target DeFi, cloud, and AI developer credentials.

Read More
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - Blog Cover Linux Kernel LPE

CVE-2026-31431 (Copy Fail): Linux Kernel LPE

New Linux 'copy_fail' LPE gives root on all major distros. Mitigate before patching.

Read More
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - Mini Shai Hulud

Shai-Hulud Strikes SAP: Supply Chain Worm Weaponized Claude Code to Compromise the CAP Framework

SAP CAP packages compromised via Claude Code in AI-assisted worm attack.

Read More
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - The Butlerian Jihad

The Butlerian Jihad: Compromised Bitwarden CLI Deploys npm Worm, Poisons AI Assistants, and Dumps GitHub Secrets

Mend.io tracks TeamPCP's latest supply chain attack.

Read More
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - Blog cover Team PCP part 4 1

A Poisoned Xinference Package Targets AI Inference Servers

Three poisoned xinference releases on PyPI target AI infrastructure credentials.

Read More
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - Blog cover Poisoned Axios

Poisoned Axios: npm Account Takeover, 50 Million Downloads, and a RAT That Vanishes After Install

See how the attack works, what to look for, and how to remediate.

Read More
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - Blog cover TEAM PCP part 3

Famous Telnyx Pypi Package compromised by TeamPCP

See how the attack works, what to look for, and how to remediate.

Read More
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - Blog cover TEAM PCP attack V2

TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer

Check and fix your install for the new LiteLLM PyPI compromise.

Read More
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - Blog cover CanisterWorm

CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive

Deep dive into the self-spreading CanisterWorm.

Read More
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - Blog Zero day Shai hulud V2

Shai-Hulud: The Second Coming

See how the latest Shai-Hulud attack works.

Read More
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - Blog cover Mend Main Blues 1

NPM Ecosystem Under Siege: Self-Propagating Malware Compromises 187 Packages in a Huge Supply Chain Attack

A major NPM breach exposed 187 packages.

Read More
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - npm supply chain attack blog

NPM Supply Chain Attack: Sophisticated Multi-Chain Cryptocurrency Drainer Infiltrates Popular Packages

A sophisticated npm supply chain attack compromised popular packages

Read More
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account - truffelvscode blog post

Fake VS Code Extension on npm Spreads Multi-Stage Malware

Learn about a fake VS-code extension on npmβ€”truffelvscodeβ€”typosquatting the popular truffle for VS-code extension.

Read More