ended5월 13일· 1 sources

Mini Shai-Hulud Worm Compromises Major Software Ecosystems via CI/CD Exploit

npm·PyPI 생태계 뒤흔든 'Mini Shai-Hulud' 공급망 웜... TanStack 등 주요 패키지 오염

Why it matters

This incident marks a dangerous evolution in supply chain attacks by weaponizing GitHub Actions and OIDC to distribute 'verified' malicious packages. It forces a critical re-evaluation of automated publishing trust models as attackers shift focus from simple typosquatting to hijacking legitimate CI/CD runners.

1
Sources
+0
24h
Growth
89d
Active
Mini Shai-HuludSupply Chain AttackTanStackGitHub ActionsOIDCTeamPCP

Sources

Related Issues