# Socket Weekly: Mini Shai-Hulud Hits npm and PyPI, NIST Audit…

Canonical: https://brew.new/browse/templates/email/pt1_k97ra50t454px6zmvr7vbk95z58e5gg9

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: Mini Shai-Hulud Hits npm and PyPI, NIST Audit…](https://cdn.brew.new/email-preview-dd354465896b3540-tracking_r57zxy80c9ab2gr8b7p8f3stxx8dttgp-1789015387311.png)

## Email content

socket-weekly-new-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

Mini Shai-Hulud, Miasma, and Hades Spread Across npm and PyPI

The Mini Shai-Hulud/Miasma/Hades cluster now spans 471 affected artifacts across npm and PyPI, including compromised Red Hat Cloud Services npm packages, a Hades/Miasma PyPI wave, and newer malicious PyPI packages targeting bioinformatics, AI, and MCP developers. The campaign goes after developer and CI/CD secrets, but the newer PyPI packages also show a more specific scanner-evasion move: a fake prompt-injection header planted before the obfuscated Hades payload to trip up naive LLM-assisted analysis.

MORE NEWS

Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD Backlog

A federal audit found that NIST and CISA used the same contractor while duplicating at least 21,000 vulnerability enrichment activities, wasting about $200,000 as the NVD backlog continued to grow. The finding puts hard numbers around a problem security teams have felt for more than two years: vulnerability data is still moving slower than the ecosystem built around it.

RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems

RubyGems and Bundler 4.0.13 added an opt-in cooldown feature that delays newly published gems during dependency resolution. Package managers are starting to treat instant availability as a security tradeoff, especially when malicious releases often do the most damage in the first minutes after publication.

MORE WORTH READING

1-Click GitHub Token Stealing via a VSCode Bug

AI, Open Source, and the Skills Imperative: Unpacking the 2026 State of Tech Talent Europe Report

Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator

The EU Open Source Strategy

Taking Stock of the State of European Cyber Resilience Act (CRA) Compliance: An Urgent Wake-up Call for the Open Source Ecosystem

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97ra50t454px6zmvr7vbk95z58e5gg9)

[Browse email designs](https://brew.new/browse/templates)
