Vulnerabilità ed exploit · Supply chain
La provenance SLSA valida non garantisce più la sicurezza dei package I controlli di provenance non chiudono più il divario di fiducia in npm e PyPI. Il worm Mini Shai-Hulud di TeamPCP ha ցույց?
17 fonti · 21 mag
Valutazione della community Threat researchers from SANS and Unit 42 describe TeamPCP’s campaign as evolving into wormable propagation with infrastructure persistence and monetization, broadening beyond the headline package compromise and indicating operational maturity before the current report.
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 9.6 CRITICAL: on 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. EPSS 1% (63º percentile).
Data di correzione federale CISA 10 giu
Cronologia Fonti 21 mag Tenable
Mini Shai-Hulud Supply Chain Attack CVE-2026-45321 FAQ | Tenable®
Mini Shai-Hulud is a self-spreading supply chain worm targeting npm and PyPI.
originale 21 mag Microsoft Security Blog
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft | Microsoft Security Blog
Compromised @antv npm packages deploy the Mini Shai-Hulud payload to steal CI/CD secrets from Linux-based automation environments.
originale 21 mag The Register Security
GitHub says internal repos exfiltrated after poisoned VS Code extension attack
Initial assessment says customer data spared while users wonder what else may have slipped out
originale Part of the PlainSec briefing for 2026-05-18
Every edition of this story: La provenance SLSA valida non garantisce più la sicurezza dei package
Altro da oggi
Vulnerabilità ed exploit · Supply chain
La provenance SLSA valida non garantisce più la sicurezza dei package I controlli di provenance non chiudono più il divario di fiducia in npm e PyPI. Il worm Mini Shai-Hulud di TeamPCP ha ցույց?
17 fonti · 21 mag
Valutazione della community Threat researchers from SANS and Unit 42 describe TeamPCP’s campaign as evolving into wormable propagation with infrastructure persistence and monetization, broadening beyond the headline package compromise and indicating operational maturity before the current report.
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 9.6 CRITICAL: on 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. EPSS 1% (63º percentile).
Data di correzione federale CISA 10 giu
Cronologia Fonti 21 mag Tenable
Mini Shai-Hulud Supply Chain Attack CVE-2026-45321 FAQ | Tenable®
Mini Shai-Hulud is a self-spreading supply chain worm targeting npm and PyPI.
originale 21 mag Microsoft Security Blog
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft | Microsoft Security Blog
Compromised @antv npm packages deploy the Mini Shai-Hulud payload to steal CI/CD secrets from Linux-based automation environments.
originale 21 mag The Register Security
GitHub says internal repos exfiltrated after poisoned VS Code extension attack
Initial assessment says customer data spared while users wonder what else may have slipped out
originale Part of the PlainSec briefing for 2026-05-18
Every edition of this story: La provenance SLSA valida non garantisce più la sicurezza dei package
Altro da oggi