Why bother hunting for a CVE when you can just publish malicious code straight into the software supply chain? That’s the story behind the latest wav e of Shai-Hulud-related np m compromises, which recently hit the Ant Design (AntV) ecosystem and potentially exposed downstream developers to credential theft and remote code execution through trusted packages. Again.
Shai-Hulud is Back: Maintainer Accounts Are Still the Soft Target
calendar_today
May 19, 2026
domain
sonatype