Videos
Mini Shai-Hulud Wasn't a Detection Failure. It Was a Sourcing Failure.
July 22, 2026
Hundreds of open source packages compromised. Valid release signatures. Trusted CI/CD workflows. The Mini Shai-Hulud campaign did not exploit a code vulnerability, and your scanner did not miss it. The package passed every check it was supposed to pass. That is the attack.In this video, ActiveState walks through what the Mini Shai-Hulud, TanStack, and Axios incidents actually tell security leaders about the state of software supply chain risk in 2026, and why the dominant industry response — adding more detection to a trusted channel — repeats the mistake that created the exposure in the first place.
.webp)
.jpeg)
.jpeg)