Claude Published PyPI Malware That Ran on 15 Real Systems

Date Observed: Disclosed July 30, 2026. Anthropic has not published the date the package went live.Ecosystem: PyPI (Python)Targets: Developer workstations, CI/CD runners, automated package scannersAttack Type: Autonomous agent-authored malicious package claiming an unregistered name; install-time credential theftImpact: Credentials exfiltrated from a security vendor’s package scanner and reused to reach further infrastructure at that company; package […]
keyv npm Supply Chain Attack: Shai-Hulud Returns

Date Observed: August 4, 2026Ecosystem: npmTargets: CI/CD runners and developer workstations consuming keyv, cacheable, flat-cache, file-entry-cache, cache-manager, plus 400+ downstream packagesAttack Type: Maintainer account compromise (initial-access method unconfirmed) leading to a self-replicating credential-stealing wormImpact: Credential theft from developer machines and CI runners, automatic republishing to every package the victim can write to Key Takeaways Introduction […]
AsyncAPI npm Supply Chain Attack Delivers Miasma RAT

Date Observed: July 14, 2026Ecosystem: npm (@asyncapi organization)Targets: Developers, CI/CD runners, and build systems consuming AsyncAPI packagesAttack Type: CI/CD compromise via GitHub Actions pull_request_target -> trojanized package publishImpact: 5 malicious versions across 4 packages, ~2.9M combined weekly downloads; import-time Miasma RAT delivery Key Takeaways Introduction On July 14, 2026, an attacker published trojanized versions of […]
Miasma npm Worm Hits LeoPlatform Packages

Date Observed: June 24, 2026 (LeoPlatform wave); follow-on @immobiliarelabs wave June 26, 2026Ecosystem: npm (primary); propagation logic also targets PyPI, RubyGems, and GoTargets: LeoPlatform / RStreams maintainer account (czirker); ~20 leo-* and rstreams-* packages, plus later @immobiliarelabs Backstage pluginsAttack Type: Self-propagating supply chain worm delivered through a build-time binding.gyp install hook (Mini Shai-Hulud / Miasma […]
Inside the Mastra npm Supply Chain Attack

Date Observed: June 17, 2026Ecosystem: npm (@mastra scope)Targets: Developer workstations and CI/CD runners installing @mastra/* packagesAttack Type: Account takeover + dependency injection + typosquatting + credential-stealing RATImpact: Over 140 packages trojanized; ~8M weekly downloads exposed; cryptocurrency wallet and credential theft Key Takeaways A Mastra contributor’s npm account was hijacked after scope permissions were never revoked, […]
Red Hat npm Supply Chain Attack: Miasma Hits @redhat-cloud-services

Date Observed: June 1, 2026Ecosystem: npm @redhat-cloud-services Targets: CI/CD pipelines and developer workstations consuming @redhat-cloud-services packages Attack Type: CI/CD pipeline compromise; preinstall hook injection; multi-stage credential theft; worm propagation Impact: At least 32 @redhat-cloud-services packages / 96 malicious versions were backdoored; multi-cloud credential theft (GitHub Actions, AWS, GCP, Azure, Kubernetes, HashiCorp Vault, CircleCI); downstream propagation capability; ~80,000 cumulative […]
Microsoft’s Durabletask PyPI Attack: Mini Shai-Hulud Saga Continues.

Date Observed: May 19, 2026Ecosystem: PyPI (Python)Targets: CI/CD runners, cloud workloads, Kubernetes clusters, developer environments consuming durabletaskAttack Type: Supply chain compromise via stolen PyPI publishing token; import-time malicious loader with multi-stage payloadImpact: Multi-cloud credential theft (AWS, Azure, GCP, Kubernetes, HashiCorp Vault, password managers); lateral movement via AWS SSM and kubectl exec; geotargeted disk wiper; persistent […]
Mini Shai-Hulud Hits @antV: Here We Go Again

Date Observed: May 19, 2026Ecosystem: npm (Node.js)Targets: @antV data visualization packages, echarts-for-react, timeago.js, size-sensor, canvas-nest.js, CI/CD pipelines, developer workstations.Attack Type: Maintainer account compromise, preinstall hook injection, optionalDependencies abuse, npm worm propagationImpact: 639 malicious package versions across 323 npm packages; 2,700+ GitHub exfiltration repositories created; cloud credentials, tokens, and SSH keys stolen Key Takeaways The npm […]
The TanStack npm Attack: How TeamPCP Compromised 42 Packages

Date Observed: May 11, 2026Ecosystem: npm, PyPITargets: Developers using @tanstack/react-router and related packages; UiPath, Mistral AI, OpenSearch, and Guardrails AI usersAttack Type: GitHub Actions cache poisoning, OIDC token extraction from runner memory, npm worm self-propagationImpact: 84 malicious package versions across 42 @tanstack/* npm packages; PyPI packages also compromised; credentials stolen from GitHub, AWS, GCP, Kubernetes, […]
BufferZoneCorp Supply Chain Attack Hits Ruby and Go

Date Observed: Late April 2026Ecosystem: RubyGems and Go ModulesTargets: Developers, CI runners, and GitHub Actions pipelinesAttack Type: Malicious package campaign, credential theft, CI poisoning, and SSH persistenceImpact: Secret exposure, build tampering, poisoned dependency resolution, and possible long-term runner access Key Takeaways The BufferZoneCorp campaign targeted developer systems and CI environments with Ruby gems and Go […]