Posts

Showing posts with the label OpenSearch
📡 Breaking news
Analyzing latest trends...

GitHub Actions Under Siege How Cache Poisoning Infiltrated the npm and PyPI Ecosystems.

Image
The Worm Returns: "Mini Shai-Hulud" Malware Targets Premier Tech Packages in Massive Supply Chain Attack Cybersecurity firm Socket has sounded the alarm after detecting a resurgence of the "Mini Shai-Hulud" malware across the npm and PyPI ecosystems. Named after the giant sandworms of Dune , this malware first gained notoriety in late 2025. Following a series of high-profile breaches in late April 2026 involving SAP, Intercom, and Lightning, the attackers have now set their sights on a new wave of essential developer tools. High-Profile Targets Identified The latest wave of infected packages includes critical software from several industry leaders: TanStack: Popular web development suite (npm) UiPath: Robotic Process Automation (npm) Mistral: Large Language Model (LLM) library (PyPI) Guardrails AI: AI safety framework (PyPI) OpenSearch: Search and analytics suite (npm) Squawk: Database linter (npm) Inside the Attack: Cache Poisoning on GitHub Actions This...