Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Mini Shai Hulud: @antv npm Supply Chain Attack & CI/CD Credential Theft
Introduction The software supply chain has suffered a significant blow with the discovery of a malicious campaign targeting the @antv npm ec...
TanStack npm Supply Chain Attack: Detecting Nx Console Compromise & GitHub Token Theft
Introduction GitHub has confirmed that the breach of 3,800 internal source code repositories was the direct result of a sophisticated supply...
Grafana GitHub Source Code Exfiltration via TanStack npm Supply Chain Attack — IR Guide
Introduction On May 19, 2026, Grafana Labs disclosed a significant security incident confirming that their GitHub environment was breached, ...
Shai-Hulud Supply Chain Attack: Detection and Remediation for 600 Compromised npm Packages
Introduction A massive supply-chain attack campaign, dubbed "Shai-Hulud," has flooded the Node Package Manager (npm) registry with over 600 ...
Malicious npm Packages: Infostealers and Phantom Bot DDoS — Detection and Removal Guide
Introduction Security researchers have identified a fresh wave of malicious packages targeting the npm ecosystem, specifically designed to c...
TanStack 'Mini Shai-Hulud' Supply Chain Attack: IOC Analysis and macOS Hardening
Introduction OpenAI recently confirmed that two of its corporate macOS devices were compromised during the TanStack supply chain attack, dub...
CVE-2022-23812: node-ipc npm Supply Chain Attack — Detection and Remediation Guide
Introduction A critical supply chain attack has compromised the node-ipc package, a widely used dependency in the JavaScript ecosystem with ...
Supply Chain Attack: Malicious Node-IPC Versions (v9.1.6, v9.2.3, v12.0.1) — Detection and Remediation
Introduction A critical supply chain compromise has been identified within the widely used node-ipc npm package. Security researchers at Soc...
Mini Shai-Hulud: Detecting SAP NPM Supply Chain Attack and Bun Binary Abuse
Introduction The open-source ecosystem faces a persistent threat from supply chain compromises, and the recent "Mini Shai-Hulud" attack camp...