Mend.io Blog

Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account

Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account

LATEST
Learn more

Filter & Search

Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - mini shai hulud is back 1

Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account

Mini Shai-Hulud strikes again: 323 npm packages compromised via @antv's atool.

Read More Read More
Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - mend securing rubygems

Inside the RubyGems Supply Chain Attack: How Mend Defender Caught a Coordinated Flood Before It Spread

How Mend.io caught a coordinated RubyGems attack and what it teaches us.

Read More Read More
Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - mini shai hulud is back

Mini Shai-Hulud Is Back: 172 npm and PyPI Packages Compromised in Latest Wave

Shai-Hulud's largest wave: 172 npm and PyPI packages compromised in 48 hours.

Read More Read More
Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - featured image mend github 1000x650

Mend.io and GitHub Partner to Bring Mend Renovate Cloud to Open Source Maintainers

Mend.io expands Renovate Cloud's OSS plan for GitHub Maintainer Month 2026.

Read More Read More
Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - crn women channel 1000x650 1

Mend.io’s Stephanie Broyles Named to CRN’s 2026 Women of the Channel List

Mend.io CMO Stephanie Broyles named to CRN's 2026 Women of the Channel list.

Read More Read More
Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - blog best sast solutions

Best SAST Solutions: How to Choose Between the Top 12 Tools in 2026

Compare 12 top SAST tools of 2026 and find the right fit for your team.

Read More Read More
Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - npm supply chain attack

PhantomRaven Wave 5: New Undocumented NPM Supply Chain Campaign Targets DeFi, Cloud, and AI Developers

33 malicious NPM packages target DeFi, cloud, and AI developer credentials.

Read More Read More
Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - blog cover linux kernel lpe

CVE-2026-31431 (Copy Fail): Linux Kernel LPE

New Linux 'copy_fail' LPE gives root on all major distros. Mitigate before patching.

Read More Read More
Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - mini shai hulud

Shai-Hulud Strikes SAP: Supply Chain Worm Weaponized Claude Code to Compromise the CAP Framework

SAP CAP packages compromised via Claude Code in AI-assisted worm attack.

Read More Read More
Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - the butlerian jihad

The Butlerian Jihad: Compromised Bitwarden CLI Deploys npm Worm, Poisons AI Assistants, and Dumps GitHub Secrets

Mend.io tracks TeamPCP's latest supply chain attack.

Read More Read More
Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - blog cover team pcp part 4 1

A Poisoned Xinference Package Targets AI Inference Servers

Three poisoned xinference releases on PyPI target AI infrastructure credentials.

Read More Read More
Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - blog zero day visibility 1000x650

From Panic to Playbook: Modernizing Zero‑Day Response in AppSec

Learn how AppSec teams build a repeatable zero-day response workflow.

Read More Read More
Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - sast all about static application security testing post

What Is SAST – Static Application Security Testing

Learn about Static Application Security Testing (SAST).

Read More Read More
Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - blog image sca tools 1

Best Software Composition Analysis (SCA) Tools: Top Solutions in 2026

Learn what SCA tools do and how they help secure your open source dependencies.

Read More Read More
Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - blog project glasswing 1000x650

Anthropic’s Project Glasswing: How Claude Mythos is Changing the Rules for AppSec

See what AI-powered offense means for your AppSec & AI Security program.

Read More Read More
Mini shai-hulud hits @antv: 323 npm packages compromised through the atool maintainer account - docker hardened images integration

Container Security Without Context Is Just More Noise

Smarter container security with Docker Hardened Images.

Read More Read More

Subscribe to our Blog

Never miss a post. Opt-out at any time.

Thank you

You’re all set to receive our latest posts.