Analysis: GitHub and Grafana Security Incidents Likely Linked to Widespread 'Mini Shai-Hulud' Supply Chain Campaign
A widespread supply chain attack dubbed 'Mini Shai-Hulud' has targeted popular npm packages and Python SDKs. Compromised accounts were used to publish malicious versions rapidly. This campaign is suspected to be connected to recent large-scale GitHub token leaks and the Grafana Labs ransomware incident. Analysis and mitigation steps are provided.
Read More