Published June 4, 2026 ยท Added June 7, 2026

New Shai-Hulud Miasma Wave Hits Hundreds of npm Packages

Sonatype reports that a new Shai-Hulud/Miasma wave compromised 281 npm package versions, using install-time payloads to steal developer and CI/CD credentials, publish malicious versions through trusted maintainer channels, and create new risks for AI-assisted development workflows.

Sonatype reports that a new Shai-Hulud/Miasma wave compromised 281 npm package versions, using install-time payloads to steal developer and CI/CD credentials, publish malicious versions through trusted maintainer channels, and create new risks for AI-assisted development workflows.

Read the original story.

Source: Sonatype