Search
For "Shai-Hulud" across CVEs, vendor advisories, threat actors, IOCs, security research, and news. Also searching: npm, supply chain, tinycolor
npm self-replicating supply-chain worm targeting popular packages, Sept-Oct 2025+.
Malicious code in embiggen (PyPI)
Malicious code in gpsea (PyPI)
Malicious code in pyphetools (PyPI)
Malicious code in phenopacket-store-toolkit (PyPI)
Malicious code in ppkt2synergy (PyPI)
Malicious code in houzidawang807 (npm)
Malicious code in houzidawang806 (npm)
Malicious code in houzidawang808 (npm)
Malicious code in postcss-minify-selector-parser (npm)
Malicious code in class-synth (npm)
Malicious code in postinstall-logger-7x9z (npm)
Malicious code in node-stack-frames (npm)
Malicious code in node-denv (npm)
Malicious code in sheratan_haha (npm)
Malicious code in node-multi-downloader (npm)
Malicious code in node-app-doctor (npm)
Malicious code in beamz (npm)
Malicious code in vite-config-react (npm)
Malicious code in vite-config-optimizer (npm)
Malicious code in ecto_module (npm)
tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix,
Malicious code in @ci-lifecycle-test/postinstall-ping (npm)
Malicious code in warp-dependency (npm)
Malicious code in ect-472839-ctf (npm)
Malicious code in ect-839201-ctf (npm)
Malicious code in ect-839201 (npm)
Malicious code in ect-654321 (npm)
Malicious code in claudechor (npm)
Malicious code in chalk-plus-ts (npm)
Malicious code in chalk-plus-js (npm)
Malicious code in workflow-postgres-setup (npm)
Malicious code in chalk-pro (npm)
Malicious code in jextic-eclib (npm)
Malicious code in vite-plugin-compress-js (npm)
Malicious code in vite-plugin-logo (npm)
esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
Malicious code in worker-build (npm)
Malicious code in vqlxjmpr (npm)
Malicious code in vite-tsconfig (npm)
Malicious code in vite-svgr (npm)
Malicious code in vite-react-toolkit (npm)
Malicious code in veteran (npm)
Malicious code in typeorm-encrypt (npm)
Malicious code in tw-fluid-type (npm)
Malicious code in ui-weave (npm)
Malicious code in ttspc-server-sample (npm)
Malicious code in ts-build-optimize (npm)
Malicious code in theta-connector (npm)
Malicious code in theta-kit (npm)
Malicious code in tango-app-api-trax (npm)