[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:happy-birthday-shai-hulud-mu9an2ju":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":18,"article_ids":19,"ioc_summary":21,"source_urls":22,"status":24,"expires_at":25,"created_at":26,"updated_at":27,"articles":28},"4759d120-37e4-4702-a9d1-1cf7a544d44f","Happy Birthday, Shai-Hulud","happy-birthday-shai-hulud-mu9an2ju","The Shai-Hulud supply chain worm has been active for one year, targeting npm packages like @ctrl\u002Ftinycolor to harvest credentials and self-propagate across development environments. The threat has evolved to exploit OIDC tokens and continues spreading through multiple waves. Any organization using compromised npm dependencies faces credential theft and potential lateral movement into their infrastructure.","critical","advisory",[],[13,14,15,16,17],"@ctrl\u002Ftinycolor","TruffleHog","CrowdStrike","npm","GitHub","Audit all npm package dependencies for @ctrl\u002Ftinycolor and known compromised packages. Rotate all developer credentials, API tokens, and OIDC tokens immediately. Scan package-lock.json files across all repos for malicious versions and block installation of flagged packages at your npm proxy.",[20],"3994502a-5152-4438-936d-17f45906ba17",null,[23],"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fhappy-birthday-shai-hulud?utm_medium=feed","active","2026-09-22T04:05:45.6+00:00","2026-09-20T04:05:48.396122+00:00","2026-09-20T04:05:51.783373+00:00",[29],{"id":20,"title":6,"url":23}]