Indicator
Type domain · source intel_report_ingest
Related reports (4)
Title/body text match only.
TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack On May 11, 2026, the Mini Shai-Hulud worm compromised 84 npm package artifacts across 42 @tanstack/* packages (as well as @squawk/*, @mistralai/* packages, and others) by chaining a GitHub Actions "
Celebrating our 2025 open-source contributions Last year, our engineers submitted over 375 pull requests that were merged into non–Trail of Bits repositories, touching more than 90 projects from cryptography libraries to the Rust compiler. This work reflects one of our driving v
Shipping huggingface_hub every week with AI, open tools, and a human in the loop Shipping huggingface_hub every week with AI, open tools, and a human in the loop Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languag
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended
Sources / connectors (1)
Deduped connector weight from graph context.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
See edges, pivots, and corroboration at a glance.
Full inspector with neighbor expansion.