Mini Shai-Halud hackers publish over 600 compromised npm packages — developers warned to be on their guard

https://www.profitableratecpm.com/f4ffsdxe?key=39b1ebce72f3758345b2155c98e6709c

  • More than 600 malicious NPM packages were released in a coordinated supply chain attack linked to TeamPCP’s Shai-Hulud campaign.
  • Attackers have compromised ecosystems such as TanStack, Mistral and antv, introducing information stealers and persistence mechanisms into development environments.
  • Developers are advised to revert to secure versions released before May 18 and rotate any exposed credentials.

Cybercriminals published more than 600 malicious packages to the npm registry in a coordinated software supply chain attack linked to the Shai-Hulud campaign.

Multiple security organizations, including Socket, have confirmed that on May 19, 2026, in just one hour, malicious actors managed to release 639 versions of 323 unique packages to npm, targeting software developers, open source maintainers, organizations running CI/CD pipelines, and anyone who downloaded or depends on the compromised npm packages.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button