SecurityHorrors

Stories you never want to feel on your own skin

19 May 2026

Mini Shai-Hulud: 639 Packages Deep and Still Burrowing

TLDR and affected package summary for the latest wave of the Mini Shai-Hulud npm supply-chain campaign targeting antv and echarts-for-react.

11 May 2026

Mini Shai-Hulud: The Package That Crawled Through CI

TLDR and affected package summary for the Mini Shai-Hulud npm and PyPI supply-chain campaign.