<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>isotope13 Supply-Chain Attack Compendium</title>
    <link>https://isotope13.io/compendium/</link>
    <atom:link href="https://isotope13.io/compendium/feed.xml" rel="self" type="application/rss+xml" />
    <description>Supply-chain attacks where an official project or vendor distribution point distributed malicious code.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 18 Sep 2026 11:55:08 GMT</lastBuildDate>
    <item>
      <title>BindsNET repository carried a forged merge commit that ran malware on folder open</title>
      <link>https://isotope13.io/compendium/2026/bindsnet/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/bindsnet/</guid>
      <pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>An attacker with a BindsNET collaborator&amp;#39;s credentials force-pushed a forged copy of an existing merge commit over 20 branches on 2026-08-29, adding a hidden Visual Studio Code task that ran malware disguised...</description>
    </item>
    <item>
      <title>Coder module registry served credential-stealing Terraform modules</title>
      <link>https://isotope13.io/compendium/2026/registry-coder-com/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/registry-coder-com/</guid>
      <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>An attacker added unauthorized IPs to the Cloudflare pool behind registry.coder.com, which served modified Terraform modules for fourteen hours on 2026-08-31. The modules ran a script that gathered provisioner...</description>
    </item>
    <item>
      <title>GitHub Actions comment trigger published malicious openapi-react-query-codegen</title>
      <link>https://isotope13.io/compendium/2026/7nohe-openapi-react-query-codegen/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/7nohe-openapi-react-query-codegen/</guid>
      <pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>A GitHub Actions release workflow fired on any pull request comment reading &amp;quot;npm publish&amp;quot;, with no check on who wrote it. An attacker used it to build, sign and publish ten malicious versions of...</description>
    </item>
    <item>
      <title>arrayref crates.io account published build-script dropper dependency</title>
      <link>https://isotope13.io/compendium/2026/arrayref/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/arrayref/</guid>
      <pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>A compromised crates.io account republished arrayref, internment, and append-only-vec on 2026-08-20 with a dependency on the typosquat proc-macro1, whose build script downloaded and ran a second stage at...</description>
    </item>
    <item>
      <title>BdThemes plugins poisoned through the vendor&#39;s banner feed</title>
      <link>https://isotope13.io/compendium/2026/bdthemes/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/bdthemes/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>Attackers with write access to BdThemes&amp;#39; promotional JSON bucket returned a crafted display_id that exploited an unescaped attribute in the vendor&amp;#39;s Biggopti banner script. The XSS ran in every admin session,...</description>
    </item>
    <item>
      <title>Vendor-side WordPress compromises seeded rogue admins</title>
      <link>https://isotope13.io/compendium/campaigns/wordpress-admin-persistence-2026/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/campaigns/wordpress-admin-persistence-2026/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <category>campaign</category>
      <description>Between June and August 2026 the same operators reached WordPress sites through three vendor-side compromises rather than through site vulnerabilities, hitting Awesome Motive&amp;#39;s CDN, the ARVE plugin&amp;#39;s source,...</description>
    </item>
    <item>
      <title>keyv and cacheable maintainer compromise seeded the ChainDrop worm</title>
      <link>https://isotope13.io/compendium/2026/jaredwray/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/jaredwray/</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>On 2026-08-04 an attacker took over the jaredwray account and republished the keyv and cacheable families with a preinstall hook that downloaded Bun and ran a credential harvester. The worm spread to 444...</description>
    </item>
    <item>
      <title>ChainDrop worm poisoned 444 npm packages in four hours</title>
      <link>https://isotope13.io/compendium/campaigns/chaindrop-2026/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/campaigns/chaindrop-2026/</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
      <category>campaign</category>
      <description>ChainDrop began with the compromise of the keyv and cacheable maintainer on 2026-08-04 and spread to 444 package names across 2,212 versions in under four hours, taking in servicetitan, ornikar, qlik, and...</description>
    </item>
    <item>
      <title>AUR adoption disabled after a second malicious commit wave</title>
      <link>https://isotope13.io/compendium/2026/arch-user-repository-2/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/arch-user-repository-2/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>A late-July 2026 wave of adopted AUR packages pushed malicious commits that dropped a validator binary into the build path, running with sudo during the build. Arch disabled package adoption on 2026-07-30 and...</description>
    </item>
    <item>
      <title>Atomic Arch turned orphaned AUR packages into infostealers</title>
      <link>https://isotope13.io/compendium/campaigns/atomic-arch-2026/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/campaigns/atomic-arch-2026/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <category>campaign</category>
      <description>Attackers adopted abandoned Arch User Repository packages through AUR&amp;#39;s own stewardship process and rewrote their PKGBUILDs to pull malicious dependencies. Waves in June and late July 2026 led Arch to disable...</description>
    </item>
    <item>
      <title>Joyfill npm beta releases carried a DEV#POPPER RAT</title>
      <link>https://isotope13.io/compendium/2026/joyfill/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/joyfill/</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>Two Joyfill beta releases published on 2026-07-28 appended an obfuscated implant after the legitimate package code. It resolved its C2 through blockchain transactions, opened a Socket.IO remote access channel,...</description>
    </item>
    <item>
      <title>ARVE WordPress plugin shipped a hardcoded admin backdoor</title>
      <link>https://isotope13.io/compendium/2026/advanced-responsive-video-embedder/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/advanced-responsive-video-embedder/</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>Version 10.8.7 of Advanced Responsive Video Embedder carried a concealed authentication bypass that logged any unauthenticated request bearing a hardcoded token in as an administrator. Wordfence PRISM found it...</description>
    </item>
    <item>
      <title>Adform tracking script hijacked to serve crypto clipper</title>
      <link>https://isotope13.io/compendium/2026/adform/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/adform/</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>Between 2026-07-26 and 2026-07-27 the official `trackpoint-async.js` served from Adform&amp;#39;s `s2.adform.net` carried a clipboard hijacker that swapped Bitcoin, Ethereum, and TRON wallet addresses on the roughly...</description>
    </item>
    <item>
      <title>Xanadu MrMustard PyPI release stole HPC and cloud credentials</title>
      <link>https://isotope13.io/compendium/2026/mrmustard/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/mrmustard/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>mrmustard 0.7.4 was uploaded to PyPI on 2026-07-23 from a hijacked maintainer account with no matching tag or commit upstream. It read SSH keys, AWS credentials, and kubeconfig on import, and installed three...</description>
    </item>
    <item>
      <title>Dormant RubyGems accounts woke up to publish a backdoor</title>
      <link>https://isotope13.io/compendium/2026/rubygems/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/rubygems/</guid>
      <pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>Attackers took over two long-idle RubyGems maintainer accounts and published the first releases in years for Dendreo and a fastlane plugin. The loader skipped CI environments and installed a persistent daemon...</description>
    </item>
    <item>
      <title>AsyncAPI npm releases carried a Miasma botnet loader</title>
      <link>https://isotope13.io/compendium/2026/asyncapi/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/asyncapi/</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>An attacker exploited a pull_request_target workflow in the AsyncAPI generator repository to steal an npm publish token, then shipped four @asyncapi packages that fetched an encrypted Miasma second stage from...</description>
    </item>
    <item>
      <title>Miasma worm rode a build-config file through npm</title>
      <link>https://isotope13.io/compendium/campaigns/miasma-2026/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/campaigns/miasma-2026/</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <category>campaign</category>
      <description>Miasma was a 2026 npm worm that stole CI and cloud credentials, then republished trojanized versions from any maintainer account it reached. It ran from the @redhat-cloud-services compromise on May 29 through...</description>
    </item>
    <item>
      <title>Jscrambler npm releases dropped a Rust infostealer</title>
      <link>https://isotope13.io/compendium/2026/jscrambler/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/jscrambler/</guid>
      <pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>An attacker with a stolen npm publishing credential shipped five malicious jscrambler releases and poisoned its webpack, gulp, grunt, and metro plugins on 2026-07-11. Later versions moved the dropper out of...</description>
    </item>
    <item>
      <title>Miasma poisoned LeoPlatform npm and jumped to a Go module</title>
      <link>https://isotope13.io/compendium/2026/leoplatform/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/leoplatform/</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>In late June 2026 the Miasma worm republished 23 LeoPlatform and RStreams npm packages with a malicious binding.gyp, then reached the Verana Blockchain Go module. It was the campaign&amp;#39;s first move outside npm,...</description>
    </item>
    <item>
      <title>Mastra npm org republished 140+ packages with a dropper dependency</title>
      <link>https://isotope13.io/compendium/2026/mastra/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/mastra/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>An attacker took over a maintainer account with publish rights across the @mastra npm organization and, in 88 minutes on 2026-06-17, republished more than 140 packages with a dependency on easy-day-js, whose...</description>
    </item>
    <item>
      <title>ShapedPlugin Pro builds backdoored in the vendor pipeline</title>
      <link>https://isotope13.io/compendium/2026/shapedplugin/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/shapedplugin/</guid>
      <pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>Attackers injected a self-deleting loader into ShapedPlugin&amp;#39;s commercial Pro plugin builds distributed through the vendor&amp;#39;s Easy Digital Downloads update endpoint. The dropped payload installed a fake...</description>
    </item>
    <item>
      <title>Awesome Motive CDN served backdoor JavaScript to 1.2M sites</title>
      <link>https://isotope13.io/compendium/2026/awesome-motive/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/awesome-motive/</guid>
      <pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>An attacker used a CDN API key found on Awesome Motive&amp;#39;s marketing server to modify the SDK files that OptinMonster, TrustPulse, and PushEngage load into customer sites. The injected script created hidden...</description>
    </item>
    <item>
      <title>Orphaned AUR packages adopted and rewritten to steal credentials</title>
      <link>https://isotope13.io/compendium/2026/arch-user-repository/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/arch-user-repository/</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>Starting 2026-06-11 attackers used the AUR&amp;#39;s orphaned-package adoption process to take over abandoned packages, then added a pacman install scriptlet that npm-installed atomic-lockfile as root at install time....</description>
    </item>
    <item>
      <title>Injective SDK release hooked wallet key derivation</title>
      <link>https://isotope13.io/compendium/2026/injective-labs/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/injective-labs/</guid>
      <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>A trusted contributor account pushed commits that wrapped the Injective SDK&amp;#39;s key derivation functions, and @injectivelabs/sdk-ts@1.20.21 shipped them to npm on 2026-06-08. Mnemonics and private keys were...</description>
    </item>
    <item>
      <title>IronWorm backdoored Arweave ecosystem npm packages</title>
      <link>https://isotope13.io/compendium/2026/asteroiddao/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/asteroiddao/</guid>
      <pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>JFrog found a Rust-built npm worm in 36 packages published from the compromised asteroiddao account, carrying an eBPF kernel rootkit and a Tor C2. It backdated commits across nine GitHub organizations and...</description>
    </item>
    <item>
      <title>Vapi server SDK caught in the Phantom Gyp npm wave</title>
      <link>https://isotope13.io/compendium/2026/vapi-ai-server-sdk/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/vapi-ai-server-sdk/</guid>
      <pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>On 2026-06-03 the Miasma worm republished 57 npm packages in under two hours, hiding execution in a 157-byte binding.gyp file instead of an install script. The largest victim was @vapi-ai/server-sdk, at more...</description>
    </item>
    <item>
      <title>Red Hat npm namespace poisoned via a maintainer&#39;s editor</title>
      <link>https://isotope13.io/compendium/2026/redhat-cloud-services/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/redhat-cloud-services/</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>An attacker used a Red Hat employee&amp;#39;s GitHub account, compromised by a malicious VS Code extension, to inject the Miasma preinstall dropper into 32 @redhat-cloud-services npm packages. Red Hat published 96...</description>
    </item>
    <item>
      <title>laravel-lang Packagist packages re-tagged from a compromised org credential</title>
      <link>https://isotope13.io/compendium/2026/laravel-lang/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/laravel-lang/</guid>
      <pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>An attacker with push access to Laravel-Lang rewrote every tag in lang, attributes, actions, and http-statuses to commits that autoloaded a credential stealer through composer. The dropper fetched a PHP second...</description>
    </item>
    <item>
      <title>Tiledesk GitHub org poisoned by Megalodon, npm followed</title>
      <link>https://isotope13.io/compendium/2026/tiledesk/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/tiledesk/</guid>
      <pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>On 2026-05-18 nine Tiledesk repositories received Megalodon&amp;#39;s Optimize-Build workflow commit. The maintainer published @tiledesk/tiledesk-server 2.18.6 through 2.18.12 from the poisoned tree between 2026-05-19...</description>
    </item>
    <item>
      <title>art-template sold to a shell company, then shipped the Coruna iOS exploit kit</title>
      <link>https://isotope13.io/compendium/2024/art-template/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2024/art-template/</guid>
      <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>The author sold `art-template` on 2024-11-17 to KILLER WHAL AI SDN BHD. The new owners shipped 4.13.3, 4.13.5, and 4.13.6 with a browser-bundle loader that fed the Coruna iOS exploit kit through utaq.cfww.shop...</description>
    </item>
    <item>
      <title>Microsoft durabletask PyPI hit by Mini Shai-Hulud</title>
      <link>https://isotope13.io/compendium/2026/durabletask/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/durabletask/</guid>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>TeamPCP published malicious durabletask 1.4.1, 1.4.2, and 1.4.3 to PyPI with a stolen token, bypassing Microsoft&amp;#39;s CI/CD path. The dropper fetched rope.pyz to harvest cloud and password-manager credentials,...</description>
    </item>
    <item>
      <title>AntV ecosystem npm packages hit by TeamPCP</title>
      <link>https://isotope13.io/compendium/2026/antv/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/antv/</guid>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>On 2026-05-19, TeamPCP took the shared `atool` npm account and published 639 malicious versions across 323 packages — most of the @antv ecosystem and a long tail of standalone neighbors. The bun-based dropper...</description>
    </item>
    <item>
      <title>Shai-Hulud hits npm and PyPI</title>
      <link>https://isotope13.io/compendium/campaigns/shai-hulud-here-we-go-again/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/campaigns/shai-hulud-here-we-go-again/</guid>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
      <category>campaign</category>
      <description>Shai-Hulud: Here We Go Again was a May 2026 TeamPCP campaign affecting roughly 169 to 170+ npm package names, plus 2 PyPI packages, with combined reported download volume above 200 million per week.</description>
    </item>
    <item>
      <title>Nx Console VS Code extension shipped credential stealer</title>
      <link>https://isotope13.io/compendium/2026/nx-console/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/nx-console/</guid>
      <pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>A compromised contributor published Nx Console 18.95.0 to the VS Code Marketplace and OpenVSX on 2026-05-18. The malicious build fetched an obfuscated payload that harvested Vault, npm, AWS, GitHub, 1Password,...</description>
    </item>
    <item>
      <title>actions-cool GitHub Actions tags rewritten by TeamPCP</title>
      <link>https://isotope13.io/compendium/2026/actions-cool/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/actions-cool/</guid>
      <pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>TeamPCP re-pointed all 53 issues-helper tags and all 15 maintain-one-comment tags to a single dangling imposter commit on 2026-05-18. The injected step downloaded Bun, scraped Runner.Worker memory for masked...</description>
    </item>
    <item>
      <title>Megalodon mass-backdoored GitHub CI workflows</title>
      <link>https://isotope13.io/compendium/campaigns/megalodon-2026/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/campaigns/megalodon-2026/</guid>
      <pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate>
      <category>campaign</category>
      <description>Between 11:36 and 17:48 UTC on 2026-05-18 an unidentified actor pushed 5,718 commits across 5,561 GitHub repositories, dropping a base64-encoded bash payload into a .github/workflows file and exfiltrating CI...</description>
    </item>
    <item>
      <title>bfunky/http-parser Packagist package backdoored with host stealer</title>
      <link>https://isotope13.io/compendium/2026/bfunky-http-parser/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/bfunky-http-parser/</guid>
      <pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>An attacker pushed an Analytics.php payload into bfunky/http-parser and re-tagged 11 historical releases on GitHub, causing Packagist to serve a host-data stealer to anyone installing the abandoned PHP HTTP...</description>
    </item>
    <item>
      <title>node-ipc npm account shipped credential stealer</title>
      <link>https://isotope13.io/compendium/2026/node-ipc/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/node-ipc/</guid>
      <pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>Three malicious node-ipc npm releases were published on 2026-05-14 after the dormant `atiertant` co-maintainer account was recovered via an expired email domain. The obfuscated payload harvested developer,...</description>
    </item>
    <item>
      <title>Mistral SDK packages imported Shai-Hulud loader</title>
      <link>https://isotope13.io/compendium/2026/mistralai-python/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/mistralai-python/</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>Mistral&amp;#39;s PyPI SDK and npm SDK packages appeared in the May 2026 Shai-Hulud wave. The affected releases carried campaign loaders through official package distribution paths.</description>
    </item>
    <item>
      <title>wot-api npm package carried Shai-Hulud</title>
      <link>https://isotope13.io/compendium/2026/wot-api/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/wot-api/</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>JFrog listed 1 wot-api npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.</description>
    </item>
    <item>
      <title>ts-dna npm package carried Shai-Hulud</title>
      <link>https://isotope13.io/compendium/2026/ts-dna/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/ts-dna/</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>JFrog listed 1 ts-dna npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.</description>
    </item>
    <item>
      <title>safe-action npm package carried Shai-Hulud</title>
      <link>https://isotope13.io/compendium/2026/safe-action/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/safe-action/</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>JFrog listed 1 safe-action npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.</description>
    </item>
    <item>
      <title>OpenSearch prereleases carried Shai-Hulud</title>
      <link>https://isotope13.io/compendium/2026/opensearch-js/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/opensearch-js/</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>Four @opensearch-project/opensearch prereleases were published with Mini Shai-Hulud malware. OpenSearch removed them and blocked repository writes during credential rotation.</description>
    </item>
    <item>
      <title>nextmove-mcp npm package carried Shai-Hulud</title>
      <link>https://isotope13.io/compendium/2026/nextmove-mcp/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/nextmove-mcp/</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>JFrog listed 1 nextmove-mcp npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.</description>
    </item>
    <item>
      <title>guardrails-ai PyPI package carried Shai-Hulud</title>
      <link>https://isotope13.io/compendium/2026/guardrails-ai/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/guardrails-ai/</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>JFrog listed 1 guardrails-ai PyPI package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.</description>
    </item>
    <item>
      <title>git-git-git npm package carried Shai-Hulud</title>
      <link>https://isotope13.io/compendium/2026/git-git-git/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/git-git-git/</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>JFrog listed 1 git-git-git npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.</description>
    </item>
    <item>
      <title>git-branch-selector npm package carried Shai-Hulud</title>
      <link>https://isotope13.io/compendium/2026/git-branch-selector/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/git-branch-selector/</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>JFrog listed 1 git-branch-selector npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.</description>
    </item>
    <item>
      <title>cross-stitch npm package carried Shai-Hulud</title>
      <link>https://isotope13.io/compendium/2026/cross-stitch/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/cross-stitch/</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>JFrog listed 1 cross-stitch npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.</description>
    </item>
    <item>
      <title>cmux-agent-mcp npm package carried Shai-Hulud</title>
      <link>https://isotope13.io/compendium/2026/cmux-agent-mcp/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/cmux-agent-mcp/</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>JFrog listed 1 cmux-agent-mcp npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.</description>
    </item>
    <item>
      <title>agentwork-cli npm package carried Shai-Hulud</title>
      <link>https://isotope13.io/compendium/2026/agentwork-cli/</link>
      <guid isPermaLink="true">https://isotope13.io/compendium/2026/agentwork-cli/</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>attack</category>
      <description>JFrog listed 1 agentwork-cli npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.</description>
    </item>
  </channel>
</rss>
