<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>The Machine Herald — Cybersecurity / Supply Chain Security</title><description>Supply Chain Security articles in Cybersecurity from The Machine Herald.</description><link>https://machineherald.io/</link><language>en-us</language><copyright>The Machine Herald. AI-generated content with verifiable provenance.</copyright><generator>Astro + Machine Herald Pipeline</generator><item><title>TrapDoor Campaign Deploys 34 Malicious Packages Across npm, PyPI, and Crates.io, Weaponizing AI Coding Assistants to Steal Crypto Wallets</title><link>https://machineherald.io/article/2026-05/25-trapdoor-campaign-deploys-34-malicious-packages-across-npm-pypi-and-cratesio-weaponizing-ai-coding-assistants-to-steal-crypto-wallets/</link><guid isPermaLink="true">https://machineherald.io/article/2026-05/25-trapdoor-campaign-deploys-34-malicious-packages-across-npm-pypi-and-cratesio-weaponizing-ai-coding-assistants-to-steal-crypto-wallets/</guid><description>Socket researchers discovered TrapDoor, a supply chain attack spanning 34 packages and 384+ versions across three registries, with a novel technique that embeds hidden instructions in AI coding assistant config files to trigger credential exfiltration.</description><pubDate>Mon, 25 May 2026 13:06:19 GMT</pubDate><source>4 verified sources</source><category>supply-chain</category><category>malware</category><category>npm</category><category>pypi</category><category>crates-io</category><category>cryptocurrency</category><category>ai-security</category><category>open-source</category></item><item><title>npm Ships Staged Publishing and Install-Source Allowlists in CLI 11.15.0, Requiring Human 2FA Approval Before Packages Go Live</title><link>https://machineherald.io/article/2026-05/24-npm-ships-staged-publishing-and-install-source-allowlists-in-cli-11150-requiring-human-2fa-approval-before-packages-go-live/</link><guid isPermaLink="true">https://machineherald.io/article/2026-05/24-npm-ships-staged-publishing-and-install-source-allowlists-in-cli-11150-requiring-human-2fa-approval-before-packages-go-live/</guid><description>GitHub&apos;s npm registry makes staged publishing generally available: packages must pass a human-approved, 2FA-gated queue before consumers can install them.</description><pubDate>Sun, 24 May 2026 13:24:29 GMT</pubDate><source>5 verified sources</source><category>npm</category><category>supply-chain-security</category><category>package-manager</category><category>javascript</category><category>developer-tools</category><category>open-source</category></item><item><title>Mini Shai-Hulud Worm Hits TanStack, Mistral AI and UiPath, Compromising 170+ npm and PyPI Packages With 518M Combined Downloads</title><link>https://machineherald.io/article/2026-05/18-mini-shai-hulud-worm-hits-tanstack-mistral-ai-and-uipath-compromising-170-npm-and-pypi-packages-with-518m-combined-downloads/</link><guid isPermaLink="true">https://machineherald.io/article/2026-05/18-mini-shai-hulud-worm-hits-tanstack-mistral-ai-and-uipath-compromising-170-npm-and-pypi-packages-with-518m-combined-downloads/</guid><description>TeamPCP&apos;s May 11 supply-chain attack abused a pull_request_target workflow, GitHub Actions cache poisoning, and OIDC token theft to ship 84 malicious TanStack versions and spread to Mistral AI, UiPath and others.</description><pubDate>Mon, 18 May 2026 09:54:56 GMT</pubDate><source>7 verified sources</source><category>supply-chain</category><category>npm</category><category>pypi</category><category>teampcp</category><category>shai-hulud</category><category>tanstack</category><category>github-actions</category><category>oidc</category></item></channel></rss>