Malware & Threats Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. Ionut Arghire1 day ago
Data Breaches Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack Hackers accessed Grafana’s GitHub repositories after a token compromised in the TanStack attack was not rotated. Ionut ArghireMay 22, 2026
Malware & Threats Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack A compromised maintainer account was used to publish malicious package versions across the @antv namespace. Ionut ArghireMay 20, 2026
Malware & Threats TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack Over 400 malicious versions of 170 packages were published as part of the new Mini Shai-Hulud campaign. Ionut ArghireMay 12, 2026
Supply Chain Security 1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom The compromised Lightning and Intercom packages have a combined monthly download count of nearly 10 million. Ionut ArghireMay 1, 2026