Mini Shai-Hulud npm worm compromises 160+ packages, abuses GitHub Actions cache + Trusted Publishing. Full list of compromised packages
TeamPCP's supply chain attack worm dubbed Mini Shai-Hulud is back and has reportedly compromised 160+ packages, including parts of the TanStack and Mistral ecosystems. The interesting part is the attack path: instead of
📄
This source provides headlines only. Use the button below to read the complete article on the original site.
📰 Read the original article on r/cybersecurity
Originally published by r/cybersecurity. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.