# malicious packages

Malicious packages are open-source packages intentionally designed to harm or compromise victims, including through unauthorized access, data leaks, resource consumption, or data destruction.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Chainguard and Upwind: Secure what you build. Verify what you run.

DevFeed: [Chainguard and Upwind: Secure what you build. Verify what you run.](<https://devfeed.tech/articles/chainguard-and-upwind-secure-what-you-build-verify-what-you-run-12926.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-and-upwind-secure-what-you-build-verify-what-you-run>)

Published: 2026-05-26T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [malicious packages](<https://devfeed.tech/topics/malicious-packages.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [chainguard-scanners](<https://devfeed.tech/tags/chainguard-scanners.md>), [chainguard-upwind](<https://devfeed.tech/tags/chainguard-upwind.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware-scanners](<https://devfeed.tech/tags/malware-scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [upwind](<https://devfeed.tech/tags/upwind.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard announces that Upwind now scans Chainguard Libraries for Python. The article describes combining trusted software artifacts with runtime visibility to reduce noise and supply chain risk.

### Source excerpt

Chainguard and Upwind combine trusted, source-built artifacts with runtime verification to cut noise, reduce risk, and secure AI-era software.

## Impact of SHA1-Hulud: The Second Coming on the Mintlify CLI

DevFeed: [Impact of SHA1-Hulud: The Second Coming on the Mintlify CLI](<https://devfeed.tech/articles/impact-of-sha1-hulud-the-second-coming-on-the-mintlify-cli-31088.md>)

Original publisher: [Read original article](<https://www.mintlify.com/blog/sha1-hulud-the-second-coming>)

Author: Han Wang

Published: 2025-11-25T00:00:00Z

Content type: news

Language: en

Sources: [Mintlify Blog](<https://devfeed.tech/sources/mintlify-blog.md>)

Topics: [Command-line interface](<https://devfeed.tech/topics/cli.md>), [npm](<https://devfeed.tech/topics/npm.md>), [malicious packages](<https://devfeed.tech/topics/malicious-packages.md>), [Security](<https://devfeed.tech/topics/security.md>), [pnpm](<https://devfeed.tech/topics/pnpm.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [deprecated](<https://devfeed.tech/tags/deprecated.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [npm](<https://devfeed.tech/tags/npm.md>), [pnpm](<https://devfeed.tech/tags/pnpm.md>), [resolved](<https://devfeed.tech/tags/resolved.md>), [security](<https://devfeed.tech/tags/security.md>), [sha1-hulud](<https://devfeed.tech/tags/sha1-hulud.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

### AI overview

Mintlify reports that its CLI was briefly exposed to the SHA1-Hulud supply chain attack through compromised npm dependencies on November 24, 2025. The company says it resolved the issue within six hours, released CLI version 4.2.210, deprecated potentially affected versions, and provided remediation steps for users who installed or updated during the vulnerable window.

### Source excerpt

The Mintlify CLI was briefly exposed to a supply chain attack. Learn what happened, who was affected, and what actions to take. Resolved in 6 hours.

## S1ngularity - What Happened, How We Responded, What We Learned

DevFeed: [S1ngularity - What Happened, How We Responded, What We Learned](<https://devfeed.tech/articles/s1ngularity-what-happened-how-we-responded-what-we-learned-21447.md>)

Original publisher: [Read original article](<https://nx.dev/blog/s1ngularity-postmortem>)

Author: Juri Strumpflohner

Published: 2025-09-05T00:00:00Z

Content type: article

Language: en

Sources: [Juri Strumpflohner](<https://devfeed.tech/sources/juri-strumpflohner.md>)

Topics: [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [npm](<https://devfeed.tech/topics/npm.md>), [malicious packages](<https://devfeed.tech/topics/malicious-packages.md>), [Security](<https://devfeed.tech/topics/security.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Local AI](<https://devfeed.tech/topics/local-ai.md>), [Claude](<https://devfeed.tech/topics/claude.md>)

Tags: [claude](<https://devfeed.tech/tags/claude.md>), [cli](<https://devfeed.tech/tags/cli.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [gemini](<https://devfeed.tech/tags/gemini.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [incident](<https://devfeed.tech/tags/incident.md>), [local-ai](<https://devfeed.tech/tags/local-ai.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [npm](<https://devfeed.tech/tags/npm.md>), [nx](<https://devfeed.tech/tags/nx.md>), [reporting](<https://devfeed.tech/tags/reporting.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>)

### AI overview

Nx describes how attackers exploited a GitHub Actions injection vulnerability to steal its npm publishing token and publish malicious Nx packages. The packages ran post-install scripts that searched for sensitive data and uploaded results to public GitHub repositories. The article also details containment, communication, investigation, and security hardening measures.

### Source excerpt

Malicious Nx packages were published to npm via GitHub Actions exploit. Learn what happened and how we enhanced security measures.