In Brief
Posted:
8:32 AM PDT · May 19, 2026
Image Credits:fotograzia / Getty Images
Hackers have compromised several popular open source projects relied on by software developers all over the world in an ongoing cyberattack.
The attacks are part of a wider campaign known as Mini Shai-Hulud, which has already compromised several open source projects and, in turn, developers and companies that use them.
In Brief
Posted:
8:32 AM PDT · May 19, 2026
Image Credits:fotograzia / Getty Images
Hackers have compromised several popular open source projects relied on by software developers all over the world in an ongoing cyberattack.

: Mini Shai-Hulud caught spreading credential-stealing malware

A fresh Mini Shai-Hulud supply chain attack has hit over 320 NPM packages, along with GitHub Actions and a VS Code extension.

Cybercrooks ruin engineers' weekends with Saturday attack

Attackers stole a limited amount of internal credential material after malware hidden in poisoned packages reached two staff…

Hundreds of packages across npm and PyPI have been compromised in a new Shai-Hulud supply-chain campaign delivering…

TeamPCP’s Mini Shai-Hulud campaign used hijacked GitHub OIDC tokens to spread a credential-stealing worm through TanStack npm…