How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Shai-Hulud is Back: Maintainer Accounts Are Still the Soft Target

calendar_today May 19, 2026 domain sonatype

Why bother hunting for a CVE when you can just publish malicious code straight into the software supply chain? That’s the story behind the latest wav e of Shai-Hulud-related np m compromises, which recently hit the Ant Design (AntV) ecosystem and potentially exposed downstream developers to credential theft and remote code execution through trusted packages. Again.

open_in_new Read original post