<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>All Blue Security</title>
    <link>https://allbluesecurity.com</link>
    <description>Security updates, practical field notes, and deep dives from All Blue Security.</description>
    <language>en</language>
    <atom:link href="https://allbluesecurity.com/feed.xml" rel="self" type="application/rss+xml"/>

    <item>
      <title>Mini Shai-Hulud Hits SAP: Four npm Packages Backdoored With a Bun-Powered Credential Harvester</title>
      <link>https://allbluesecurity.com/blog/sap-npm-backdoor/</link>
      <description>Four SAP npm packages were backdoored with a preinstall hook that fetches the Bun runtime and executes an 11.7 MB credential harvester, draining GitHub tokens, cloud secrets, and live CI pipeline secrets from memory.</description>
      <pubDate>Wed, 29 Apr 2026 00:00:00 +0000</pubDate>
      <guid isPermaLink="true">https://allbluesecurity.com/blog/sap-npm-backdoor/</guid>
    </item>

    <item>
      <title>Mini Shai-Hulud Jumps to PyPI: Lightning Package Backdoored to Drain Developer Credentials</title>
      <link>https://allbluesecurity.com/blog/lightning-pypi-backdoor/</link>
      <description>The Mini Shai-Hulud campaign reaches PyPI: two malicious versions of the lightning Python package harvest developer credentials, cloud secrets, and wallet data from affected machines.</description>
      <pubDate>Thu, 30 Apr 2026 00:00:00 +0000</pubDate>
      <guid isPermaLink="true">https://allbluesecurity.com/blog/lightning-pypi-backdoor/</guid>
    </item>

    <item>
      <title>Axios NPM Hijack: Maintainer Account Compromised, RAT Deployed</title>
      <link>https://allbluesecurity.com/blog/axios-npm-hijack/</link>
      <description>A breakdown of the March 2026 axios supply-chain attack: how the maintainer account was hijacked, how the RAT was deployed, and how to check if you were affected.</description>
      <pubDate>Tue, 31 Mar 2026 00:00:00 +0000</pubDate>
      <guid isPermaLink="true">https://allbluesecurity.com/blog/axios-npm-hijack/</guid>
    </item>

  </channel>
</rss>
