Wednesday, October 7, 2026ArchiveSearchAsk the paper

The Computomatix Times

All the posts fit to save — curated from @computomatix's bookmarks & likes on X

Edition of Tuesday, August 4, 2026

2 stories

Microsoft Warns of Mini Shai-Hulud npm Supply Chain Attack

Microsoft Warns of Mini Shai-Hulud npm Supply Chain Attack

Microsoft Threat Intelligence reports an active npm supply chain attack that compromised maintainer accounts and published credential-stealing packages including keyv and servicetitan packages. The malware self-propagates by republishing infected package versions.

Original post · 1 min read
Microsoft Threat Intelligence is tracking active Mini Shai-Hulud npm supply chain attacks in which a threat actor compromised trusted maintainer accounts to distribute credential-stealing malware.

Compromised packages (confirmed malicious) include:
- keyv@6.0.0
- file-entry-cache@11.1.6
- cache-manager@7.2.10
- cacheable-request@13.0.20
- qlik/api@2.14.2
- cacheable/memory, /utils, /net
- 17+ servicetitan/* packages (eslint-config, anvil-themes, table, form, log-service, etc.)

In this attack, a malicious preinstall hook launches an obfuscated dropper (setup.mjs) that downloads a Bun binary from GitHub and executes a credential-stealing payload, either Math_Symbol.js or Math_Init.js.

The payload is a Mini Shai-Hulud variant, a self-propagating npm supply-chain malware family. It harvests npm, GitHub, cloud and continuous integration (CI) credentials, exfiltrates collected secrets, and uses stolen publishing access to inject itself into package tarballs, increment their versions and republish the compromised releases.

Microsoft observed the same pattern across all affected packages, suggesting a single actor using multiple stolen tokens.

Microsoft Defender for Endpoint customers should act on these alerts: “Trojan:npm/MalBun.A”
♥ 1.1K · ⟲ 239 · 👁 1.3MView on X ↗

Npm Supply Chain Worm Compromises 868 Packages, Shai-Hulud Returns

Npm Supply Chain Worm Compromises 868 Packages, Shai-Hulud Returns

A post reports an active npm supply chain attack affecting at least 868 packages with over 2 billion monthly installs, starting with a compromised keyv maintainer account. The malware uses a preinstall hook to steal npm, GitHub, AWS, Kubernetes and Vault secrets and spread to other maintainers.

Original post · 1 min read
‼️ BREAKING: An active npm supply chain attack has compromised at least 868 packages carrying over 2 billion monthly installs with a credential-stealing worm. Shai-Hulud is back.

It started with the compromise of the GitHub account of the maintainer behind keyv, a library with roughly 127 million weekly npm downloads.

A preinstall hook fires on npm install and drops a stealer that sweeps npm, GitHub, AWS, Kubernetes and Vault secrets, and then spreads to more maintainers.
♥ 8.7K · ⟲ 1.3K · 👁 1.4MView on X ↗