Product
node-gyp
- First Reported
- Aug 28, 2026
- Latest Reported
- Aug 28, 2026
Reported Context (1)
- Python expression to reach os.system and run node 3FWCvzduYZg.js. Because binding.gyp is processed by node-gyp during installation, this fires on npm install in developer environments and CI runners. Mini Shai-Hulud Supply-Chain Attack Compromises 10 npm Package Versions
MITRE ATT&CK (12)
Vendors (5)
Products (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.