Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:microsoft_mstic, report:snyk_blog, report:talos, report:the_hacker_news, report:unit42
tags: report:the_hacker_news, report:unit42
tags: report:talos, report:the_hacker_news
tags: report:microsoft_mstic, report:the_hacker_news
tags: report:talos, report:unit42
tags: report:the_hacker_news
tags: report:the_hacker_news
tags: report:the_hacker_news
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft Compromised @antv npm packages deploy the Mini Shai-Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and targets credentials across
Leaked n8n API Tokens Exposed Live Instances to Credential Theft GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without
TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack On May 11, 2026, the Mini Shai-Hulud worm compromised 84 npm package artifacts across 42 @tanstack/* packages (as well as @squawk/*, @mistralai/* packages, and others) by chaining a GitHub Actions "
The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1) Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Up
Deduped connector weight from graph context.