r/cybersecurity 🔐 Cybersecurity 👁 0

Mini Shai-Hulud npm worm compromises 160+ packages, abuses GitHub Actions cache + Trusted Publishing. Full list of compromised packages

TeamPCP's supply chain attack worm dubbed Mini Shai-Hulud is back and has reportedly compromised 160+ packages, including parts of the TanStack and Mistral ecosystems. The interesting part is the attack path: instead of

Mini Shai-Hulud npm worm compromises 160+ packages, abuses GitHub Actions cache + Trusted Publishing. Full list of compromised packages
📄

This source provides headlines only. Use the button below to read the complete article on the original site.

📰 Read the original article on r/cybersecurity

Originally published by r/cybersecurity. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.