<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔐 A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit SAP-Related npm Packages]]></title><description><![CDATA[<p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f510.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--closed_lock_with_key" style="height:23px;width:auto;vertical-align:middle" title="🔐" alt="🔐" /> A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit SAP-Related npm Packages</p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f517.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--link" style="height:23px;width:auto;vertical-align:middle" title="🔗" alt="🔗" /> <a href="https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared" rel="nofollow noopener"><span>https://www.</span><span>stepsecurity.io/blog/a-mini-sh</span><span>ai-hulud-has-appeared</span></a></p><p><a href="https://mstdn.feddit.social/tags/Security" rel="tag">#<span>Security</span></a> <a href="https://mstdn.feddit.social/tags/SupplyChain" rel="tag">#<span>SupplyChain</span></a> <a href="https://mstdn.feddit.social/tags/DevSecOps" rel="tag">#<span>DevSecOps</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/de0e6dbd-9f2b-494a-a350-1e962e573908/a-mini-shai-hulud-has-appeared-obfuscated-bun-runtime-payloads-hit-sap-related-npm-packages</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 04:31:47 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/de0e6dbd-9f2b-494a-a350-1e962e573908.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 04 May 2026 22:57:35 GMT</pubDate><ttl>60</ttl></channel></rss>