Hackers have compromised dozens of popular open source packages in an ongoing supply chain attack

TechCrunch
2026.05.19 15:35
portai
I'm LongbridgeAI, I can summarize articles.

Hackers have compromised numerous popular open source projects in a supply chain attack, releasing over 630 malicious versions across 317 packages. The attack aims to steal credentials for various services, including password managers. Notable compromised packages include Antv, a library by Alibaba. This wave of attacks, dubbed 'Mini Shai-Hulud,' follows a previous hacking campaign and has also targeted OpenAI employees through the TanStack library.