Threats Tagged 'trinitite'
View all threats tagged with 'trinitite'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'trinitite'
Click on any threat for detailed analysis and mitigation recommendations
Shai-Hulud Trinitite Hits @7nohe/openapi-react-query-codegen 0 A new Mini Shai-Hulud worm variant named Trinitite was detected on August 28, 2026, targeting the npm package @7nohe/openapi-react-query-codegen, a TanStack Query codegen tool with over 150K weekly downloads. The attacker exploited a workflow vulnerability that allowed any GitHub user to trigger npm publish via pull-request comments, publishing ten malicious versions in twenty minutes. The worm uses XOR-wrapped loaders and obfuscated binding.gyp files to execute even when scripts are disabled. It steals credentials from GitHub, npm, PyPI, RubyGems, cloud services, Vault, and Kubernetes, exfiltrating data via GitHub commits. The malware establishes persistence through systemd services and includes a token revoke trap that can wipe user directories. This campaign appeared shortly after TeamPCP suspects were arrested in Australia, using the same toolkit but with new RSA keys and graffiti. Join the discussion | AlienVault OTX General | 08/31/2026, 15:26:41 UTC Added: 09/01/2026, 08:37:15 UTC |
Showing 1 to 1 of 1 result