Valid provenance is not valid code: a supply-chain worm shipped with a valid SLSA attestation
This story is from 2026-09-03. It is preserved in the archive; the latest stories are on the live feed.
In May 2026, a supply-chain worm did something the security community had been warning about for years: it got the receipt. According to Akamai's analysis, the May 11–12 wave of the Mini Shai-Hulud campaign didn't steal an npm token. It poisoned a GitHub Actions CI cache through a fork-pull-request…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-03 06:30 · DEV Community — AI
Valid provenance is not valid code: a supply-chain worm shipped with a valid SLSA attestation
More stories
- Anthropic says Claude 'leads' 26 percent of its AI R&D work — Engadget
- Gemini Hacked Three Companies in First Known Breakout by Google’s AI — Wall Street Journal Technology
- Introducing Kimi K3 on Amazon Bedrock — AWS Machine Learning Blog
- Optimizing agent system prompts with Amazon Bedrock AgentCore — AWS Machine Learning Blog
- Introducing Amazon SageMaker HyperPod Inference Gateway — AWS Machine Learning Blog
- Introducing Astra for Law — OpenAI News
- Alibaba ships Qwen3.8-Omni-Flash to watch, listen and call tools — r/LocalLLM
- OpenAI reveals cases of ‘concerning’ AI behaviour as it announces new disclosure system — The Guardian AI
Get the daily brief of stories like this at 6:30 every morning →