The Hacker Group Turning Supply Chain Attacks Into a Sport | Threat Wire
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A cybersecurity news roundup covering several major software supply chain incidents. The mini Shai Hulud worm compromised 373 npm packages across 169 namespaces by exploiting GitHub Actions cache poisoning and OIDC token extraction, affecting TanStack, Mistral AI, OpenSearch, and others. The hacker group Team PCP open-sourced the worm and launched a $1,000 competition on Breach Forums for the largest supply chain attack. RubyGems was simultaneously hit by a coordinated bot attack publishing 500+ malicious packages targeting XSS data exfiltration. Additional news includes a critical 15-year-old Nginx RCE vulnerability (CVE-2026-42945, CVSS 9.2), hackers stealing the Grafana codebase via stolen GitHub tokens, Linux kernel's new policy treating AI-discovered bugs as public, and Apple adding end-to-end encryption to RCS messaging in iOS 26.5.