Mend.io Blog

Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave

Mini Shai-Hulud Is Back: 172 npm and PyPI Packages Compromised in Latest Wave

LATEST
Learn more

Filter & Search

Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - mini shai hulud is back

Mini Shai-Hulud Is Back: 172 npm and PyPI Packages Compromised in Latest Wave

33 malicious NPM packages target DeFi, cloud, and AI developer credentials.

Read More Read More
Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - crn women channel 1000x650 1

Mend.io’s Stephanie Broyles Named to CRN’s 2026 Women of the Channel List

Mend.io CMO Stephanie Broyles named to CRN's 2026 Women of the Channel list.

Read More Read More
Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - blog best sast solutions

Best SAST Solutions: How to Choose Between the Top 12 Tools in 2026

Compare 12 top SAST tools of 2026 and find the right fit for your team.

Read More Read More
Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - npm supply chain attack

PhantomRaven Wave 5: New Undocumented NPM Supply Chain Campaign Targets DeFi, Cloud, and AI Developers

33 malicious NPM packages target DeFi, cloud, and AI developer credentials.

Read More Read More
Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - blog cover linux kernel lpe

CVE-2026-31431 (Copy Fail): Linux Kernel LPE

New Linux 'copy_fail' LPE gives root on all major distros. Mitigate before patching.

Read More Read More
Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - mini shai hulud

Shai-Hulud Strikes SAP: Supply Chain Worm Weaponized Claude Code to Compromise the CAP Framework

SAP CAP packages compromised via Claude Code in AI-assisted worm attack.

Read More Read More
Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - the butlerian jihad

The Butlerian Jihad: Compromised Bitwarden CLI Deploys npm Worm, Poisons AI Assistants, and Dumps GitHub Secrets

Mend.io tracks TeamPCP's latest supply chain attack.

Read More Read More
Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - blog cover team pcp part 4 1

A Poisoned Xinference Package Targets AI Inference Servers

Three poisoned xinference releases on PyPI target AI infrastructure credentials.

Read More Read More
Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - blog zero day visibility 1000x650

From Panic to Playbook: Modernizing Zero‑Day Response in AppSec

Learn how AppSec teams build a repeatable zero-day response workflow.

Read More Read More
Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - sast all about static application security testing post

What Is SAST – Static Application Security Testing

Learn about Static Application Security Testing (SAST).

Read More Read More
Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - blog image sca tools 1

Best Software Composition Analysis (SCA) Tools: Top Solutions in 2026

Learn what SCA tools do and how they help secure your open source dependencies.

Read More Read More
Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - blog project glasswing 1000x650

Anthropic’s Project Glasswing: How Claude Mythos is Changing the Rules for AppSec

See what AI-powered offense means for your AppSec & AI Security program.

Read More Read More
Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - docker hardened images integration

Container Security Without Context Is Just More Noise

Smarter container security with Docker Hardened Images.

Read More Read More
Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - blog ai application security 1000x650

AI Application Security: 6 Focus Areas and Critical Best Practices

Learn how AI application security differs from traditional AppSec.

Read More Read More
Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - blog cover poisoned axios

Poisoned Axios: npm Account Takeover, 50 Million Downloads, and a RAT That Vanishes After Install

See how the attack works, what to look for, and how to remediate.

Read More Read More
Mini shai-hulud is back: 172 npm and pypi packages compromised in latest wave - blog cover team pcp part 3

Famous Telnyx Pypi Package compromised by TeamPCP

See how the attack works, what to look for, and how to remediate.

Read More Read More

Subscribe to our Blog

Never miss a post. Opt-out at any time.

Thank you

You’re all set to receive our latest posts.