Tag

#Shai-Hulud

7 stories taggedShai-Hulud.

Photoreal news-editorial style, 16:9 framing
Identity & Access

Shai-Hulud Worm Now Hunts 469 Places for Developer Secrets

A self-spreading credential thief has more than doubled the hiding spots it checks on developer machines, from 189 to 469.

4 min read
an abstract image of a digital supply chain with a malicious code hidden within
Threat Intelligence

Australian Police Arrest Two Alleged Members of Supply-Chain Extortion Crew TeamPCP

The Western Australia arrests target a group blamed for a year-long run of open-source software attacks, including the Shai-Hulud worm that hit thousands of companies.

4 min read
Full-frame edge-to-edge overhead photoreal shot of a developer workstation at night: mechanical keyboard, two monitors glowing with abstract code editor windows
Threat Intelligence

Most of the 2,500 organisations hit in the LiteLLM attack were actually victims of a different breach entirely

A closer look at the data shows the Trivy scanner compromise, not the LiteLLM package, caused almost all the damage, and stolen credentials are already on sale.

4 min read
Threat Intelligence

Mini Shai-Hulud Worm Jumps to Go, Hits LeoPlatform and RStreams npm Packages

The self-propagating supply chain campaign tied to Miasma and Hades has spread again — abusing GitHub Actions workflows and now reaching Go modules.

2 min read
Vulnerabilities

Microsoft Ships Record 200-Bug Patch Tuesday as 'Nightmare Eclipse' Drops Windows Zero-Days

AI-assisted bug hunting, a confrontational researcher, and a Shai-Hulud worm variant inside Microsoft's own repos shape an outsized June rollup.

3 min read
Threat Intelligence

Hades Hits PyPI: 37 Poisoned Wheels Auto-Exec via .pth Trick

A fresh splinter of the Miasma supply-chain campaign abuses Python's site-packages path hook to fire on import — and goes hunting for Bun credentials.

2 min read
Vulnerabilities

Miasma Campaign Infects Red Hat npm Packages

Latest supply chain attack reveals persistent threat of credential theft

2 min read
© 2026 Threat Vectr