Mend.io Blog

Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign

Miasma: Red Hat Cloud Services npm Packages Hit by a Mini Shai-Hulud-Style Campaign

LATEST
Learn more

Filter & Search

Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - shai hulud miasma

Miasma: Red Hat Cloud Services npm Packages Hit by a Mini Shai-Hulud-Style Campaign

Compromised @redhat-cloud-services npm packages drop a multi-cloud credential stealer via a malicious preinstall hook.

Read More Read More
Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - blog cover threat news

Laravel-Lang Composer tag-rewrite Supply Chain Attack

Four Laravel-Lang Composer packages were poisoned via tag rewrite.

Read More Read More
Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - featured image the eu cyber resilience act 1000x650

The EU Cyber Resilience Act: A Complete Compliance Guide for 2026 and Beyond

Everything companies need to know about EU CRA compliance before 2027.

Read More Read More
Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - mini shai hulud is back 1

Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account

Mini Shai-Hulud strikes again: 323 npm packages compromised via @antv's atool.

Read More Read More
Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - mend securing rubygems

Inside the RubyGems Supply Chain Attack: How Mend Defender Caught a Coordinated Flood Before It Spread

How Mend.io caught a coordinated RubyGems attack and what it teaches us.

Read More Read More
Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - mini shai hulud is back

Mini Shai-Hulud Is Back: 172 npm and PyPI Packages Compromised in Latest Wave

Shai-Hulud's largest wave: 172 npm and PyPI packages compromised in 48 hours.

Read More Read More
Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - featured image mend github 1000x650

Mend.io and GitHub Partner to Bring Mend Renovate Cloud to Open Source Maintainers

Mend.io expands Renovate Cloud's OSS plan for GitHub Maintainer Month 2026.

Read More Read More
Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - crn women channel 1000x650 1

Mend.io’s Stephanie Broyles Named to CRN’s 2026 Women of the Channel List

Mend.io CMO Stephanie Broyles named to CRN's 2026 Women of the Channel list.

Read More Read More
Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - blog best sast solutions

Best SAST Solutions: How to Choose Between the Top 12 Tools in 2026

Compare 12 top SAST tools of 2026 and find the right fit for your team.

Read More Read More
Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - npm supply chain attack

PhantomRaven Wave 5: New Undocumented NPM Supply Chain Campaign Targets DeFi, Cloud, and AI Developers

33 malicious NPM packages target DeFi, cloud, and AI developer credentials.

Read More Read More
Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - blog cover linux kernel lpe

CVE-2026-31431 (Copy Fail): Linux Kernel LPE

New Linux 'copy_fail' LPE gives root on all major distros. Mitigate before patching.

Read More Read More
Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - mini shai hulud

Shai-Hulud Strikes SAP: Supply Chain Worm Weaponized Claude Code to Compromise the CAP Framework

SAP CAP packages compromised via Claude Code in AI-assisted worm attack.

Read More Read More
Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - the butlerian jihad

The Butlerian Jihad: Compromised Bitwarden CLI Deploys npm Worm, Poisons AI Assistants, and Dumps GitHub Secrets

Mend.io tracks TeamPCP's latest supply chain attack.

Read More Read More
Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - blog cover team pcp part 4 1

A Poisoned Xinference Package Targets AI Inference Servers

Three poisoned xinference releases on PyPI target AI infrastructure credentials.

Read More Read More
Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - blog zero day visibility 1000x650

From Panic to Playbook: Modernizing Zero‑Day Response in AppSec

Learn how AppSec teams build a repeatable zero-day response workflow.

Read More Read More
Miasma: red hat cloud services npm packages hit by a mini shai-hulud-style campaign - sast all about static application security testing post

What Is SAST – Static Application Security Testing

Learn about Static Application Security Testing (SAST).

Read More Read More

Subscribe to our Blog

Never miss a post. Opt-out at any time.

Thank you

You’re all set to receive our latest posts.