#0001
Mini Shai-Hulud Returns: 314 `npm` Packages Compromised
60radar
A short publish window still pushed hundreds of malicious versions. Lockfiles, token hygiene, and dependency review matter before the next npm install.
- The
atoolnpmaccount was compromised on May 19, 2026, and malicious releases were pushed for about 22 minutes. - Attack automation produced 637 malicious versions across roughly 317 packages. Short-lived incidents still reach CI fast.
- The payload was a 498KB obfuscated Bun script, matching scanner structure and regexes tied to Mini Shai-Hulud.
- Targets included cloud credentials such as AWS keys. Rotate exposed tokens and audit recent installs from affected packages.
Source: news.hada.io/topic?id=29709Read original →