
0:00-23:16
Streams straight from the publisher. PodNod never proxies or re-hosts episode audio.
Scott and Wes break down the “Mini Shai-Hulud” supply chain attack that compromised TanStack and other popular npm packages through a clever GitHub Actions cache poisoning exploit; a self-propagating worm that stole credentials and persisted through Claude Code hooks and VS Code tasks. They also cover how developers can protect themselves using pnpm’s security defaults, dev containers, and other practical defenses.
Show Notes
- 00:00 Welcome to Syntax!
- 00:25 Understanding the Shai-Hulud Worm
- 02:47 Mechanics of the Attack: GitHub Actions and Cache
- 05:44 Brought to you by Sentry.io
- 06:09 Propagation and Impact of the Worm
- 09:30 Preventative Measures for Developers
- 12:33 The Role of Package Managers in Security
- 18:39 Using Dev Containers
- 20:57 Conclusion and Final Thoughts
Hit us up on Socials!
Syntax: X Instagram Tiktok LinkedIn Threads
Wes: X Instagram Tiktok LinkedIn Threads
Shai-Hulud Worm
wiz.ioPost Mortem of Shai Hulud Attack
posthog.comSocket.dev
socket.devStep Security
stepsecurity.ioSentry.io
sentry.ioDead Man’s Switch
x.comBlock Exotic Subdeps
pnpm.ioWhy You Should Use Dev Containers
youtube.comScott Tolinski’s Security Review
github.comSentry has Skills!
github.comX
twitter.comInstagram
instagram.comTiktok
tiktok.comLinkedIn
linkedin.comThreads
threads.netX
twitter.comInstagram
instagram.comTiktok
tiktok.comLinkedIn
linkedin.comThreads
threads.netX
twitter.comInstagram
instagram.comTiktok
tiktok.comLinkedIn
linkedin.comThreads
threads.netX
twitter.comInstagram
instagram.comYouTube
youtube.comThreads
threads.net