GitHub NPM Supply Chain Attack - Investigation Report
Date: May 29, 2026
Case ID: ONCHAIN-2026-0529-002
Threat Names: Megalodon, Mini Shai-Hulud
Status: Active - Ongoing Crisis
GitHub NPM Supply Chain Attack - Investigation Report Date: May 29, 2026 Case ID:...
GitHub NPM Supply Chain Attack - Investigation Report
Date: May 29, 2026
Case ID: ONCHAIN-2026-0529-002
Threat Names: Megalodon, Mini Shai-Hulud
Status: Active - Ongoing Crisis

Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week

New IronWorm malware hits 36 packages in npm supply-chain attack

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

Supply Chain Attack Hits 32 Red Hat NPM Packages

IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks

Rust-Written IronWorm Hits NPM Supply Chain

A fresh Mini Shai-Hulud supply chain attack has hit over 320 NPM packages, along with GitHub Actions and a VS Code extension.

The Megalodon supply chain attack poisoned over 5,500 GitHub repositories via automated commits injecting GitHub Actions…

Security researchers say 5,500 GitHub repositories have been affected by the attack.

A 700-repo npm supply-chain campaign drops /tmp/.sshd and bolts a fake "Dependency Cache Sync" step into your GitHub Actions.…

TeamPCP’s Mini Shai-Hulud campaign used hijacked GitHub OIDC tokens to spread a credential-stealing worm through TanStack npm…

Threat actors earlier today published more than 600 malicious packages to the Node Package Manager (npm) index as part of a new…