meta_pixel
Tapesearch Logo
Log in
Syntax - Tasty Web Development Treats

1004: TanHacked

Syntax - Tasty Web Development Treats

Wes Bos

Tech News, Technology, News

4.91.2K Ratings

🗓️ 13 May 2026

⏱️ 23 minutes

🧾️ Download transcript

Summary

Scott and Wes break down the “Mini Shai-Hulud” supply chain attack that compromised TanStack and other popular npm packages through a clever GitHub Actions cache poisoning exploit; a self-propagating worm that stole credentials and persisted through Claude Code hooks and VS Code tasks. They also cover how developers can protect themselves using pnpm’s security defaults, dev containers, and other practical defenses. Show Notes 00:00 Welcome to Syntax! 00:25 Understanding the Shai-Hulud Worm Post Mortem of Shai Hulud Attack 02:47 Mechanics of the Attack: GitHub Actions and Cache How the attack happened Who Was Involved in the Attack Several npm latest releases are compromised Socket.dev Step Security 05:44 Brought to you by Sentry.io 06:09 Propagation and Impact of the Worm 09:30 Preventative Measures for Developers Dead Man’s Switch 12:33 The Role of Package Managers in Security Block Exotic Subdeps 18:39 Using Dev Containers Why You Should Use Dev Containers Scott Tolinski’s Security Review 20:57 Conclusion and Final Thoughts Sentry has Skills! Hit us up on Socials! Syntax: X Instagram Tiktok LinkedIn Threads Wes: X Instagram Tiktok LinkedIn Threads Scott: X Instagram Tiktok LinkedIn Threads Randy: X Instagram YouTube Threads

Transcript

Click on a timestamp to play from that location

0:00.0

Tan Stack got tan hacked.

0:03.1

Verselle got their walled garden penetrated.

0:06.2

After stealing content for years, UDemmy got their content stolen.

0:11.4

Loveable, they got their vibes snatched.

0:14.4

And now NPM and Pi Pi have been hit with a major supply chain attack targeting several popular JavaScript and

0:23.6

Python packages. This is Shy Leboof. I mean, shy Hulud, which is the latest worm in a series

0:32.4

of shy Hulud worms, the original shy Hulud worm showed up back in September 2025, which feels like a century

0:41.5

ago at this point. And where malicious versions of multiple popular packages were published to NPM,

0:47.4

they contained the post-install script that harvested sensitive data and sent it to GitHub public repose named Shy Hulud.

0:57.4

So that's why we have the name Shy Hulut here.

0:59.9

I also think that's a Star Star Wars thing.

1:02.1

Shy Hulud.

1:03.0

That's a sick hardcore band.

1:05.0

If you're into hardcore music, look up Shy Hulud, sick band.

1:08.7

It's actually from the movie Dune, by the way, in case you were wondering.

1:14.4

We're just going to run through pissing off people here.

1:18.2

The new Shai Hulud 2.0 dropped in November 2025, and Post-Hog got their hog posted,

1:27.4

and Zapier got zapped, and Postman also got their hog posted. And Zapier got zapped.

1:29.4

And Postman also got their hog posted with the new Shy Hulood.

1:33.9

And then it struck again, Shai Hulub 3.0 in December of 2025.

1:40.0

And now, I don't know why they don't call this one, Shy Huloo 4.0, but this is mini Shihalud. Yes, this is mini Shihiloh. Yes, right. It is mini. It's a little mini worm. Wes, Shai Hulud is a worm in Dune just in case you want to get the reference if you've never seen the Dune movie, which I assume you have. This is insane. We're going to go through what happened,

2:03.1

how it happened, what did it do, and how you can protect yourself, but like, man, I'm tired.

...

Transcript will be available on the free plan in 6 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from Wes Bos, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of Wes Bos and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.