Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
…GitHub Actions OIDC tokens and PATs Git credentials npm publish tokens AWS Secrets Manager, IAM, and ESC task credentials Kubernetes service account tokens and cluster credentials HashiCorp Vault tokens SSH keys Claude…