Mini Shai-Hulud: The npm & pip Supply Chain Vulnerability Burrowing Through Your Stack
A newly identified supply chain attack campaign — dubbed Mini Shai-Hulud — is silently compromising developer environments by planting malicious packages in npm and PyPI. Here is how it works, who is at risk, and what you need to do right now.