GitHub NPM Supply Chain Attack - Investigation Report
Date: May 29, 2026
Case ID: ONCHAIN-2026-0529-002
Threat Names: Megalodon, Mini Shai-Hulud
Status: Active - Ongoing Crisis
GitHub NPM Supply Chain Attack - Investigation Report Date: May 29, 2026 Case ID:...
GitHub NPM Supply Chain Attack - Investigation Report
Date: May 29, 2026
Case ID: ONCHAIN-2026-0529-002
Threat Names: Megalodon, Mini Shai-Hulud
Status: Active - Ongoing Crisis

Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks

Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week

New IronWorm malware hits 36 packages in npm supply-chain attack

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

Supply Chain Attack Hits 32 Red Hat NPM Packages

IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks

GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections

A fresh Mini Shai-Hulud supply chain attack has hit over 320 NPM packages, along with GitHub Actions and a VS Code extension.

The Megalodon supply chain attack poisoned over 5,500 GitHub repositories via automated commits injecting GitHub Actions…

Mini Shai-Hulud-linked malware compromises 23 npm packages and a Verana Go module to steal developer credentials.

Security researchers say 5,500 GitHub repositories have been affected by the attack.

A 700-repo npm supply-chain campaign drops /tmp/.sshd and bolts a fake "Dependency Cache Sync" step into your GitHub Actions.…

TeamPCP’s Mini Shai-Hulud campaign used hijacked GitHub OIDC tokens to spread a credential-stealing worm through TanStack npm…