Back
Tool
Bun
Related CVEs
Recent activity
Tensorlake npm Package Compromised by Shai-Hulud WormOn October 8, 2026, the Tensorlake npm package version 0.5.144 was compromised, delivering a credential-stealing worm known as Shai-Hulud. The malware, which was published through …Remote Code Execution Vulnerabilities Found in OpenCode and OpenMedA remote code execution (RCE) vulnerability (GHSA-632h-h47v-g4x4) was discovered in OpenCode, an open-source AI coding agent, affecting versions prior to 1.18.22. The vulnerability…Mini Shai-Hulud Supply Chain Attack Targets SAP npm PackagesA new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injectin…NWHStealer Malware Campaign Evolves with Bun Loader and Anti-VM TechniquesThe NWHStealer infostealer has adopted a new distribution method utilizing the Bun JavaScript runtime, enhancing its delivery infrastructure. This Rust-based malware targets Window…Shai-Hulud npm Payload Resurfaces After 111 Days DormancyA known malicious npm payload, associated with the Shai-Hulud attack on @AntV, has resurfaced after 111 days of inactivity. The original attack occurred on May 19, 2026, when a com…Blockchain C2 Malware Targets Cloud Credentials in Supply Chain AttacksRecent campaigns involving the ChainDrop npm worm and the PolinRider operation have exploited blockchain networks as command-and-control (C2) infrastructure to steal cloud credenti…Over 400 npm Packages Infected by Credential-Stealing WormA self-replicating worm, identified as a variant of Mini Shai-Hulud, has compromised over 400 npm packages from various unrelated publishers. The malware is designed to steal devel…Shai Hulud npm Worm Compromises Over 26,000 RepositoriesThe Shai Hulud worm has compromised more than 26,000 public repositories in a supply chain attack. The attack targeted various npm packages, exploiting vulnerabilities that allowed…Axios CVE-2026-40175: Critical Vulnerability Misrepresented as Easily ExploitableA critical vulnerability in Axios, tracked as CVE-2026-40175, was reported with a CVSS score of 9.9, suggesting potential for remote code execution (RCE) and cloud infrastructure c…