A highly coordinated supply chain attack compromised 56 npm packages across 286 versions by abusing the binding.gyp native build configuration to silently execute malicious code during installation. The multi-stage, heavily encrypted payload targets CI/CD environments to harvest cloud credentials, propagates via stolen OIDC tokens, and establishes persistence with a destructive dead man's switch.
HashiCorp Vault
4 posts
How 56 npm packages used binding.gyp to steal CI/CD secrets TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack A sophisticated supply-chain worm dubbed 'Mini Shai-Hulud' has compromised numerous high-profile npm and PyPI packages, including TanStack and Mistral AI. The heavily obfuscated payload targets CI/CD environments to systematically harvest credentials from GitHub, AWS, Vault, and Kubernetes. It autonomously propagates by minting npm publish tokens and committing malicious code to repositories, while exfiltrating stolen secrets via the Session P2P network.
Cyber Centre Daily Advisory Digest — 2026-04-17 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting recent security updates for Microsoft Edge, HashiCorp Vault, and JetBrains YouTrack. Organizations are advised to apply the necessary patches to address vulnerabilities including Denial-of-Service and Server-Side Request Forgery.
Machine Learning Operations: Yesterday, Today, and Tomorrow Akamai details its internal Machine Learning Operations (MLOps) platform, highlighting the transition from manual model management to a standardized, Kubeflow-based infrastructure. The platform enhances real-time security detections by streamlining model evaluation, tuning, and deployment, and is currently evolving to support LLMOps and AgentOps for generative AI applications.