| Mini Shai-Hulud is a self-propagating supply-chain worm targeting npm, PyPI, and RubyGems. It abuses CI/CD pipelines, stolen tokens, and trusted publishing flows to spread malicious packages and steal credentials. | Blog |
How the TanStack and RubyGems Supply Chain Attacks Worked
calendar_today
May 20, 2026
domain
harness