
Mini Shai-Hulud: Cross-Ecosystem Supply Chain Attack Hits npm, PyPI, and Packagist
Date Observed: April 29–30, 2026Ecosystem: npm, PyPI, Packagist (PHP)Targets: SAP enterprise developers, AI/ML engineers, DevOps and DevSecOps teams using Intercom

Date Observed: April 29–30, 2026Ecosystem: npm, PyPI, Packagist (PHP)Targets: SAP enterprise developers, AI/ML engineers, DevOps and DevSecOps teams using Intercom

Date Observed: April 23, 2026 Ecosystem: npm (Node.js) Targets: Developer workstations, GitHub Actions CI/CD pipelines, cloud environments, AI coding tool

Date Observed: April 22, 2026Ecosystem: PyPI (Python)Targets: AI/MLOps teams, CI/CD pipelines, cloud-connected LLM inference environmentsAttack Type: Supply chain compromiseImpact: SSH

Latest release (v1.1.38) delivers real-time encoded secret interception, deep dependency intelligence, and expanded GitHub Actions support Houston, TX, April 21,

Axios npm Compromise: North Korea-Linked Threat Actor Poisons Popular HTTP Client Date Observed: March–April 2026 Ecosystem: npm, Node.js, CI/CD pipelines

TeamPCP Supply Chain Campaign: CI/CD Pipeline Attacks Targeting Trivy, KICS, and LiteLLM Date Observed: March 2026Ecosystem: GitHub Actions, npm, PyPITargets:

GlassWorm: The Invisible Unicode Supply Chain Worm Targeting CI/CD Pipelines Date Observed: October 2025 – ongoing (March 2026) Ecosystem: VS

SANDWORM_MODE: A New Wave of npm Supply Chain Attacks Targeting CI/CD Pipelines Date of Discovery: February 20, 2026Ecosystem: npmType of

Hackerbot-Claw: AI-Driven Pull Request Exploits in GitHub Actions CI/CD Date Observed: Late February 2026 Ecosystem: GitHub Actions CI/CD Attack Type:

Why Traditional DevOps Security Tools Miss CI/CD Pipeline Attacks by Tom Hamilton, CTO and Co-Founder, InvisiRisk, Inc. Key Takeaways: The