Shai-Hulud's npm worm persists via .claude + VS Code configs, with a token-revoke dead-man's switch. https://intel.threadlinqs.com/threat/TL-2026-3216 #ThreatIntel #ShaiHulud #Mini #npm

Shai-Hulud's npm worm persists via .claude + VS Code configs, with a token-revoke dead-man's switch. https://intel.threadlinqs.com/threat/TL-2026-3216 #ThreatIntel #ShaiHulud #Mini #npm
ChainDrop npm worm reads its C2 from an Ethereum contract - and scrapes CI runner memory for OIDC tokens. https://intel.threadlinqs.com/threat/TL-2026-3214 #ThreatIntel #DEVPOPPER #ShaiHulud #BeaverTail
Revoke the stolen token and this npm worm wipes your home directory. Tensorlake 0.5.144 is backdoored. https://intel.threadlinqs.com/threat/TL-2026-3085 #ThreatIntel #ShaiHulud #phantom #HackBrowserData
A malicious Tensorlake release runs on installation, before a developer uses it.
Aikido says it seeks credentials and can spread to other projects.…
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm reconbee.com/tensorlake-n...
#tensorlake #npmpackage #npm #shaihulud #credential #cybersecurity #cyberattack
Tensorlake version 0.5.144 contained Shai-Hulud, designed to steal access credentials and spread through packages a user could publish.
The releas…
Tensorlake 0.5.144 was hijacked by a worm stealing credentials, persisting via AI tool configs. Remove it now. #ShaiHulud #SupplyChain #AI #CloudSecurity #CredentialTheft #DevSecOps https://thedailytechfeed.com/tensorlake-npm-package-hijacked-by-shai-hulud-worm-threat/
A hijacked keyv maintainer shipped a npm worm with valid SLSA provenance - and it republishes itself. https://intel.threadlinqs.com/threat/TL-2026-2822 #ThreatIntel #ChainDrop #ShaiHulud #Bun
개발자 자격증명 을 노린 Shai-Hulud 악성코드-_index.js
wezard4u.tistory.com/429884
#개발지 #악성코드 #ShaiHulud
Mini Shai-Hulud hijacked on npm - one preinstall hook drains CI/CD and cloud secrets. https://intel.threadlinqs.com/threat/TL-2026-2806 #ThreatIntel #BackdoorPython #ShaiHulud #Bun
#GitHub Actions re-enabled with Mini #ShaiHulud payload still active
GitHub re-enabled a hacked Action without cleaning its tags - the credential thief woke right back up. https://intel.threadlinqs.com/threat/TL-2026-2661 #ThreatIntel #Mini #ShaiHulud #One
Rest In Peace Chad Gilbert.
Chad Gilbert PSA for Musicians Opposed to Bullying, 2012. Source: Ytube Photobycourtneymob. #chadgilbert #newfoundglory #shaihulud #outofstepdotnet #punkrock #hardcorepunk #poppunk #hazenstreet #musiciansopposedtobullying
Chad Gilbert passed from life to life this morning. I knew him and his family in the mid to late 90s and 2000s. I will always cherish his excitement for life. He will always be loved and forever held in my heart. @profoundhatred.bsky.social #chadgilbert #shaihulud #newfoundglory #2000s
AI coding assistant hijacked: poisoned deps led to Shai-Hulud worm in 100 repos. #Security #AI #ShaiHulud #SupplyChain #DevSecOps #Malware thedailytechfeed.com/ai-coding-se...
Guess the programming term in the comments!
📢 Shai-Hulud : un payload npm identique réapparu après 111 jours de dormance
Le 19 mai 2026, une attaque de chaîne d'approvisionnement baptisée Shai-Hulud avait compromis des comptes mainteneurs npm pour publier 639 versions…
🟢 vérification factuelle haute
#ShaiHulud #npm #Cyberveille
GitGuardian Honeytokens plant decoys across developer fleets, catching infostealers like Shai-Hulud as soon as stolen credentials are used, with near-zero false positives. #GitGuardian #Honeytokens #ShaiHulud
Companies cleaning up after the Shai-Hulud supply chain worm often use their own software internally, so restoring a rebuilt system can bring the malware straight back. Sygnia's responders say the fix is to rebuild pipelines from trusted sources, not just delete…
Shai-Hulud’s latest version searches 469 locations for access keys, up from 189.
The concern is not just theft: one key may lead to company code, other systems or software publ…
https://en.hacks.gr/to-shai-hulud-psachnei-pleon-se-469-simeia-gia-stoicheia-prosvasis/