Find notable cyber news and cases, enriched with sources, timelines, and signals.

Xanadu hit by network compromise

Incident
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

Xanadu confirmed a GitHub account breach that enabled a poisoned mrmustard 0.7.4 release, putting SSH private keys, AWS credentials, and Kubernetes configurations at risk. The rogue package turned routine imports into credential theft and sent data to metrics.femboy[.]energy. Attackers appear to have probed the project’s self-hosted CI runners to recover publishing secrets before pushing the malicious version. The compromise raises follow-on access risk for a research and HPC environment that relies on the library.

Related Happenings

Mastra @mastra/* npm packages hit by network compromise

Incident
H score47 First: 17.06.2026 10:38 Last: 17.06.2026 10:38 Sources 1

About this happening: Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the acti...

Latest development: 20.06.2026 17:09

Microsoft attributed the Mastra AI supply chain attack to Sapphire Sleet, also known as BlueNoroff, and said the attackers compromised the npm maintainer account ehindero, which had publishing privileges across the Mastra package environment. The June 19 update said more than 140 packages in the @mastra scope were modified to inject easy-day-js.

IronWorm npm supply-chain infection and self-propagation

Malware Activity
H score15 First: 04.06.2026 18:25 Last: 04.06.2026 18:25 Sources 1

About this happening: IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...

JINX-0164 cryptocurrency recruitment-lure campaign

Campaign
H score39 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...

AUDIOFIX and MiniRAT macOS malware activity

Malware Activity
H score34 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...

TanStack hit by network compromise

Incident
H score29 First: 12.05.2026 17:45 Last: 12.05.2026 17:45 Sources 1

About this happening: TanStack was hit by a package compromise on May 11, 2026, when attackers published 84 malicious versions across 42 @tanstack/* packages and abused the release...

Latest development: 21.05.2026 11:00

On May 17, 2026, Grafana Labs said an unauthorized attacker had downloaded its codebase after accessing the firm's GitHub environment, and the company later said additional internal operational information and business contact names and email addresses were taken from its GitHub repositories; Grafana Labs said there was no indication that customer production systems or the Grafana Cloud platform were compromised.

Timeline

  1. 03.08.2026 21:43 2 articles · 1h ago

    Xanadu maintainer account breach pushes poisoned mrmustard 0.7.4

    Initial Disclosure

    Unknown threat actors compromised Xanadu's primary maintainer GitHub account and pushed a poisoned mrmustard 0.7.4 release that runs an information stealer on package import. The malicious package targets research and HPC environments by harvesting SSH private keys, AWS credentials, and Kubernetes configurations and exfiltrating them to metrics.femboy[.]energy.

    Show sources