ended5월 13일· 1 sources
Mini Shai-Hulud Worm Compromises Major Software Ecosystems via CI/CD Exploit
npm·PyPI 생태계 뒤흔든 'Mini Shai-Hulud' 공급망 웜... TanStack 등 주요 패키지 오염
Why it matters
This incident marks a dangerous evolution in supply chain attacks by weaponizing GitHub Actions and OIDC to distribute 'verified' malicious packages. It forces a critical re-evaluation of automated publishing trust models as attackers shift focus from simple typosquatting to hijacking legitimate CI/CD runners.
1
Sources
+0
24h
—
Growth
89d
Active
Mini Shai-HuludSupply Chain AttackTanStackGitHub ActionsOIDCTeamPCP