Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type sha256 · source intel_report_ingest
Title/body text match only.
GitHub internal repositories breached <p>A malicious VS Code extension led to cloned private repositories, reportedly offered for sale on a criminal forum</p> Categories: Threat Research Tags: GitHub, Supply chain GitHub internal repositories breached | SOPHOS Skip to Content O
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft Compromised @antv npm packages deploy the Mini Shai-Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and targets credentials across
Alternate hashes joined by a persisted same-file relationship.
Alternate digest of the same reported file
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Alternate digest of the same reported file
Deduped connector weight from graph context.
From stored enrichment entities only.