‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack

2026-05-13T02:51:44Z59e9f511efc6909e7cd603aba7aa49568913191c392ab1a801e573ab11a53aa7
ai-assisted-exploitdata-breachextortiongovernment-policyintrusion-loggingmalwaremicrosoft-patch-tuesdayopen-sourcepackage-registriespatch-managementrelease-signature-spoofingsbomshinyhunterssoftware-updatessupply-chainzero-day

What happened

Multiple CyberScoop stories highlight an active, high-impact threat landscape: a sprawling supply‑chain campaign dubbed “Mini Shai‑Hulud” has compromised hundreds of open‑source packages across major registries by abusing legitimate-looking release signatures and the software update process; Google researchers also observed an AI-developed zero‑day before widespread exploitation; Microsoft’s May Patch Tuesday fixed 137 vulnerabilities (13 critical); and data‑extortion activity (ShinyHunters) targeted Instructure/Canvas affecting thousands of schools. Coverage also notes advances in device for‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
59e9f511efc6909e7cd603aba7aa49568913191c392ab1a801e573ab11a53aa7
Enrichment time
2026-05-13T02:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack · Baitaphish