Shai-Hulud worm copycats emerge after source code leak

2026-05-19T08:51:43Zd748797981b8de398e22f78d2b052b7241f984c0fcbf1bc42913b47c7e2b6cec
7-elevenactive-exploitationaws-s3-misconfigurationcldflt.syscve-2026-42945data-breache-skimmerfunnel-buildergithub-tokengrafanamalwareminiplasmanginxnpmpii-exposureprivilege-escalationpwn2ownshinyhunterssource-code-leaksupply-chaintoken-compromisewindows-zero-daywordpressworm

What happened

Feed of multiple high-impact incidents: the Shai-Hulud worm source code leak spawned fast copycat supply-chain attacks targeting NPM; Grafana confirmed a GitHub token compromise exposing source code; ShinyHunters claim theft of >600k Salesforce/franchisee records from 7‑Eleven; a misconfigured Amazon S3 bucket exposed >1M passports/IDs/selfies from Japanese hotel platform Tabiq. Significant vulnerabilities and active exploitation were reported: critical NGINX flaw CVE-2026-42945 is being actively exploited, a new Windows SYSTEM privilege-escalation zero-day (“MiniPlasma” affecting cldflt.sys)/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d748797981b8de398e22f78d2b052b7241f984c0fcbf1bc42913b47c7e2b6cec
Enrichment time
2026-05-19T08:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Shai-Hulud worm copycats emerge after source code leak · Baitaphish