News

Shai-Hulud: What to Know About the Malware Spreading Through Software Pipelines

  • Jason Nelson--Decrypt
  • published date: 2026-05-20 23:00:04 UTC

The Shai-Hulud supply-chain malware campaign is exploiting the automated systems developers trust to publish software safely.

In brief <ul><li>Shai-Hulud malware has been linked to roughly 300 npm and PyPI package entries.</li><li>OpenAI, Microsoft, and Mistral AI disclosed recent Shai-Hulud-related incidents.</li><li>The … [+5841 chars]