telexed ~ c / a65bf716-823radar:60 · otherLIVE
← back
NO.
#a65bf716
Topic
OTHER
Source
GeekNews
Published
2026-05-20 20:59:55
Importance
★ 6/10 — radar 60
Mini Shai-Hulud Returns: 314 `npm` Packages Compromised
FIG-0651:1

Mini Shai-Hulud Returns: 314 `npm` Packages Compromised

A short publish window still pushed hundreds of malicious versions. Lockfiles, token hygiene, and dependency review matter before the next npm install.

[ KEY POINTS ]
  1. The atool npm account was compromised on May 19, 2026, and malicious releases were pushed for about 22 minutes.
  2. Attack automation produced 637 malicious versions across roughly 317 packages. Short-lived incidents still reach CI fast.
  3. The payload was a 498KB obfuscated Bun script, matching scanner structure and regexes tied to Mini Shai-Hulud.
  4. Targets included cloud credentials such as AWS keys. Rotate exposed tokens and audit recent installs from affected packages.
Originalnews.hada.io/topic?id=29709Read original →

// related