Show notes
Scott and Wes break down the “Mini Shai-Hulud” supply chain attack that compromised TanStack and other popular npm packages through a clever GitHub Actions cache poisoning exploit; a self-propagating worm that stole credentials and persisted through Claude Code hooks and VS Code tasks. They also cover how developers can protect themselves using pnpm’s security defaults, dev containers, and other practical defenses.Show NotesPost Mortem of Shai Hulud AttackHow the attack happenedWho Was Involved in the AttackSeveral npm latest releases are compromisedSocket.devStep SecurityDead Man’s SwitchBlock Exotic SubdepsWhy You Should Use Dev ContainersScott Tolinski’s Security ReviewSentry has Skills!Hit us up on Socials!Syntax: X Instagram Tiktok LinkedIn ThreadsWes: X Instagram Tiktok LinkedIn ThreadsScott: X Instagram Tiktok LinkedIn ThreadsRandy: X Instagram YouTube Threads



