Vulnerabilità ed exploit · Supply chain

La provenance SLSA valida non garantisce più la sicurezza dei package

I controlli di provenance non chiudono più il divario di fiducia in npm e PyPI. Il worm Mini Shai-Hulud di TeamPCP ha ցույց?

17 fonti · 21 mag

Valutazione della community

Threat researchers from SANS and Unit 42 describe TeamPCP’s campaign as evolving into wormable propagation with infrastructure persistence and monetization, broadening beyond the headline package compromise and indicating operational maturity before the current report.

CVE-2026-45321

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 9.6 CRITICAL: on 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. EPSS 1% (63º percentile).

Data di correzione federale CISA 10 giu

Cronologia

Fonti

Part of the PlainSec briefing for 2026-05-18

Every edition of this story: La provenance SLSA valida non garantisce più la sicurezza dei package

Altro da oggi