Daily brief at 7am Melbourne. Unsubscribe any time.

Wednesday 13 May 2026

The Worm That Signed Its Own Warrants: Mini Shai-Hulud's Six-Minute Supply Chain Blitz

A self-propagating supply chain worm tore through npm and PyPI in minutes, poisoning packages from TanStack, Mistral AI, and others — and it was signed.

Lead story

The Worm That Signed Its Own Warrants: Mini Shai-Hulud's Six-Minute Supply Chain Blitz

In roughly six minutes, a threat actor known as TeamPCP pushed 84 malicious versions of popular npm packages — and they were cryptographically signed, which is the part that should keep you up at night.

The campaign, dubbed Mini Shai-Hulud, targeted packages from TanStack (a widely used React tooling ecosystem), Mistral AI, UiPath, OpenSearch, and Guardrails AI. Each poisoned package contained an obfuscated JavaScript file called router_init.js designed to profile the host environment, harvest credentials, and in some versions, wipe disk contents. The PyPI side of the campaign was running simultaneously.

What makes this different from the usual supply chain nastiness is the signing. Package signing is supposed to be the answer to "how do I know this code is legitimate?" — it's the mechanism that lets developers trust automated dependency updates. When attackers can sign malicious packages, the trust signal inverts. Your pipeline sees a signed package and waves it through. The attacker has turned your security control into a welcome mat.

The Register's reporting describes it as a "cache-poisoning caper" — the attackers appear to have compromised the signing keys or publishing credentials for existing, legitimate packages rather than creating lookalike fakes. That's a materially harder attack to pull off, and a materially harder one to detect.

RubyGems simultaneously locked new account signups after a separate major malicious upload campaign hit the Ruby package ecosystem on the same day. Whether the two are coordinated is unclear, but the timing is striking.

For defenders and developers, the immediate checklist is: audit your dependency lock files for any of the named packages updated in the last 48 hours, rotate credentials on any CI/CD system that may have processed the affected packages, and check your pipeline logs for outbound connections initiated during build steps. The Shai-Hulud campaign specifically targets the build environment — not just end users — so production systems that never directly ran the packages may still be compromised if a developer's machine or CI runner fetched them.

The bigger picture is that this is the third major supply chain incident in two weeks, following the Checkmarx Jenkins plugin compromise and the fake OpenAI Hugging Face repo. The pattern isn't coincidental — attackers have clearly identified the open source package ecosystem as the path of least resistance into enterprise environments. The fact that packages can be signed and still be malicious forces a rethink of what "verified" means in a dependency graph.

Australian organisations using JavaScript or Python toolchains — which is essentially everyone — should treat any TanStack, Mistral AI client libraries, or OpenSearch packages updated in the last week as suspect until verified. The ACSC's guidelines on software supply chain security (updated in 2025) recommend pinning dependencies to known-good commit hashes for critical pipelines, not just version numbers. This is exactly the scenario those guidelines anticipated.

The six-minute window between first push and detection is the real signal here. At that speed, even a well-monitored registry doesn't have time to react before the damage is done.

Also today

copy.fail: The Linux Privilege Escalation You Need to Patch Now

Security researcher and blogger Bruce Schneier is calling it the worst Linux vulnerability in years — and he's not being dramatic. The copy.fail flaw, disclosed by Theori in late April with a working proof-of-concept, abuses the kernel crypto API (AF_ALG sockets) combined with splice() to write arbitrary bytes directly into the page cache of files the attacker doesn't own. The exploit works unmodified across Ubuntu, RHEL, Debian, SUSE, Amazon Linux, Fedora, and most other mainstream distributions — no race condition required, no per-distro offsets to tune. Local privilege escalation to root. Patches are rolling out now; install them. Australian cloud and on-premises Linux deployments should treat this as urgent.

Schneier on Security

Microsoft Patches 137 Vulnerabilities in May Patch Tuesday

Microsoft's May 2026 Patch Tuesday is a big one: 137 vulnerabilities addressed across Windows, Azure, Dynamics 365, and the SSO Plugin for Jira and Confluence, with 13 rated critical. Notably, none are zero-days — a relative mercy. CyberScoop flags an interesting meta-story here: the unusually high volume of CVEs reflects a growing trend of AI models being deployed to find previously unknown code defects, effectively accelerating the vulnerability discovery pipeline on both sides of the fence. The Windows 10 KB5087544 extended security update and Windows 11 cumulative updates are available now. Patch early this month.

SecurityWeek

Apple and Google Finally Bring E2E Encryption to Cross-Platform Texting

iOS 26.5 has landed in beta with end-to-end encrypted RCS messaging between iPhone and Android users — no third-party app required. It's a cross-industry effort backed by the GSMA's new RCS E2EE specification. For years, iPhone-to-Android messages defaulted to unencrypted SMS, a gap security advocates have hammered at for a decade. The encryption only kicks in when both sender and recipient are on supported carriers and recent OS versions, so it won't be universal immediately. But the direction of travel is clear: the green bubble era of plaintext cross-platform messaging is winding down. Australian carriers' readiness to enable the feature will determine how quickly local users see the benefit.

The Hacker News

OpenAI Launches Daybreak: AI-Powered Vulnerability Detection and Patch Validation

OpenAI has unveiled Daybreak, a cybersecurity initiative pairing its frontier models with its Codex agentic harness to help organisations find and fix vulnerabilities before attackers do. The pitch is that Daybreak can both identify flaws and validate that patches actually resolve them — closing a loop that human-led security teams often leave open. Partners are involved, though OpenAI hasn't named all of them publicly yet. It's a direct play in the AI-for-defence market, and it lands in the same week that CyberScoop noted AI models are already inflating the volume of CVEs discovered — meaning the tools accelerating attack surface growth are now also being sold as the remedy.

The Hacker News

Foxconn Confirms Cyberattack Hitting North American Factories

Foxconn has confirmed a cyberattack affecting its North American manufacturing operations, with plants across Wisconsin, Ohio, Texas, Virginia, Indiana, and Mexico impacted. The company took systems offline but declined to specify how many factories were affected or what data may have been exfiltrated. Foxconn is the world's largest electronics contract manufacturer and assembles products for Apple, Microsoft, Sony, and others. Given Australia's significant imports of consumer electronics from Foxconn's supply chain, any prolonged operational disruption could affect product availability and delivery timelines downstream. This is a story to watch — the company has been hit before, and past incidents have involved ransomware groups.

The Record

West Pharmaceutical Services Taken Down by Ransomware

West Pharmaceutical Services, a major maker of drug packaging and delivery components — including the vials and stoppers used in vaccine manufacturing — has disclosed a ransomware attack that began on 4 May. Hackers exfiltrated data before encrypting systems globally, forcing the company to take infrastructure offline. West filed an SEC disclosure on Monday. The attack is notable for its sector: pharmaceutical supply chain disruptions have direct public health implications, and West's components are used by drug manufacturers worldwide. It joins a growing list of critical manufacturers targeted by ransomware groups in 2026.

SecurityWeek

Instructure Paid the Ransom — And Congress Wants Answers

Instructure, the company behind the Canvas learning platform used by millions of students, has confirmed it reached a financial agreement with ShinyHunters to prevent the leak of 3.65TB of stolen data from more than 8,800 school systems. The company says hackers returned the data and provided digital confirmation of destruction — neither of which is independently verifiable. The US Congress has now launched an investigation. Paying a ransom guarantees nothing; it funds the next attack and normalises extortion as a viable business model. For Australian schools using Canvas — including several university consortiums — this is a useful prompt to revisit third-party data handling and extortion response policies under the Privacy Act.

The Record

Google and Amnesty International Built a Spyware Detection Tool Into Android

Google has quietly launched a significant new feature in Android: Intrusion Logging, developed in partnership with Amnesty International's Security Lab. The feature, part of Android's Advanced Protection Mode, creates tamper-evident logs of device activity that can help forensic analysts detect sophisticated spyware — including commercial tools like Pegasus. Amnesty International called it the first feature from a major device vendor specifically designed to aid spyware forensics. It's primarily aimed at journalists, human rights defenders, and dissidents. Australia has no domestic commercial spyware industry to speak of, but Australian journalists and activists operating internationally are potential targets of foreign state-sponsored tools this feature could help catch.

CyberScoop

Japan's PM Orders Cybersecurity Review Over AI-Accelerated Attack Fears

Japan's Prime Minister has ordered a government-wide cybersecurity review, specifically citing concerns about Anthropic's Mythos model dramatically increasing the speed and scale of cyberattacks. The directive reflects growing anxiety among national security establishments that next-generation AI models will compress the time attackers need to develop and deploy exploits — shrinking defender response windows to near zero. Japan's review follows similar postures from the UK's NCSC and CISA in the US. Australia's ACSC has not yet issued a public statement on Mythos specifically, though the Defence Strategic Review identified AI-accelerated threats as a key concern for the 2025–2030 horizon.

The Register

A US Bank Self-Reported After Employees Fed Customer Data to an Unauthorised AI App

A US bank has voluntarily reported itself to regulators after discovering that staff had uploaded a significant volume of sensitive customer data to an unauthorised AI application. The bank cited both the volume and the sensitivity of the data as the core concern in its self-disclosure. The incident is a near-textbook example of shadow AI risk: employees find a productivity tool, start using it, and the data governance team finds out months later. Australian financial institutions regulated by APRA under CPS 234 and the revised Privacy Act have explicit obligations to assess third-party data handling — including AI tools employees adopt informally — and this kind of incident would trigger mandatory notification requirements here.

The Register

Trail of Bits Forked the Go Toolchain to Fix Fuzzing's Blind Spots

Security firm Trail of Bits has published a detailed write-up of gosentry, a fuzzing-oriented fork of the Go toolchain designed to close the gap between Go's native fuzzing capabilities and the far more mature tooling available for Rust, C, and C++. The problem: Go's built-in fuzzer misses entire bug classes — integer overflows, goroutine leaks, data races, execution timeouts. Gosentry adds coverage-guided instrumentation and structured input generation while preserving the standard testing.F workflow developers already know. For any team running Go in production — which increasingly includes fintech, cloud infrastructure, and developer tooling — this is worth reading as a reference for hardening your testing pipeline.

Trail of Bits

Sources consulted