<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[One infection, two registries.]]></title><description><![CDATA[<p>One infection, two registries. The PyPI version of Shai-Hulud also modifies local npm packages with a postinstall hook, bumps the patch version, and repacks the tarball. Publish from your local environment and the malware spreads to npm.</p><p>The attack surface is not one registry. It is all of them.</p><p><a href="https://mstdn.social/tags/SupplyChain" rel="tag">#<span>SupplyChain</span></a> <a href="https://mstdn.social/tags/PyPI" rel="tag">#<span>PyPI</span></a> <a href="https://mstdn.social/tags/npm" rel="tag">#<span>npm</span></a> <a href="https://mstdn.social/tags/Infosec" rel="tag">#<span>Infosec</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/31b20806-b7ce-4766-bf0b-36268975501c/one-infection-two-registries.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 04:34:27 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/31b20806-b7ce-4766-bf0b-36268975501c.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 30 Apr 2026 20:08:40 GMT</pubDate><ttl>60</ttl></channel></rss>