# Socket Weekly: Mini Shai-Hulud Attack Spreads Across 3 Open Source…

Canonical: https://brew.new/browse/templates/email/pt1_k97h79qsg6nenaydc50syv7a4h8e45ac

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: Mini Shai-Hulud Attack Spreads Across 3 Open Source…](https://cdn.brew.new/email-preview-25a71c6e8e676b68-tracking_r57rzdmmwmgskq4b33ajpfp7wn8dt7ph-1789015370629.png)

## Email content

socket-weekly-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP Package Follows npm Compromise

Mini Shai-Hulud was the week’s biggest supply chain story, starting with TeamPCP-linked compromises of SAP CAP and Cloud MTA npm packages before escalating into a compromise that wormed its way across 3 ecosystems: PyPI PyTorch lightning → npm intercom-client → Packagist intercom/intercom-php. The attack shows how one compromised developer environment can become a bridge into the next package compromise, turning local installs, stolen credentials, and package publishing workflows into a path for spreading across open source ecosystems.

MORE NEWS

Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables

In one of the wilder supply chain attacks we’ve seen lately, a maintainer sitting on the unscoped tanstack npm package tried to extort TanStack’s creator for $10,000, turned the package into “TanStack Player” for backlinks, and then shipped versions that stole .env files during install. In a now-deleted post on X, the maintainer apologized and claimed the malware was accidental AI-agent testing that he “forgot to remove” because he was studying for exams, which somehow makes the story even more bizarre.

Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI

A cross-ecosystem supply chain campaign used Ruby gems and Go modules that looked like normal developer tools, with some sitting dormant as sleeper packages before later updates added credential theft, GitHub Actions tampering, Go proxy manipulation, fake go wrappers, and SSH persistence.

MORE WORTH READING

Copy Fail: 732 Bytes to Root on Every Major Linux Distribution.

cPanel & WHM Authentication Bypass

PyPI Fixes High-Severity Access Control Issues Found in Security Audit

Securing the git push pipeline: Responding to a critical remote code execution vulnerability

How the PyTorch Lightning Community Discovered a Supply Chain Attack and Fixed it in 42 Minutes

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97h79qsg6nenaydc50syv7a4h8e45ac)

[Browse email designs](https://brew.new/browse/templates)
