GeistHaus
log in · sign up

TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages - StepSecurity

stepsecurity.io

The Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. StepSecurity's OSS Package Security Feed first detected the attack in official @tanstack packages and is tracking its spread across the ecosystem in real time.

16 pages link to this URL
OpenAI hit by supply chain attack linked to malicious TanStack packages

OpenAI said the TanStack supply chain attack compromised two employee devices and exposed credentials from code repositories.

0 inbound links article en Breaking NewsCyber CrimeHackingSecurity CybercrimeHackinghacking newsinformation security newsIT Information SecuritymalwareMini Shai-HuludOpenAIPierluigi PaganiniSecurity AffairsSecurity Newssupply chain attack
npm Is on Fire — Vivian Voss

Wire Fire Episode 01. Six weeks of supply-chain compromise on the npm registry, ending on 12 May 2026 with the Shai-Hulud worm source going public. 31 March: state-sponsored operators (Microsoft Sapphire Sleet, Mandiant UNC1069) backdoor axios versions 1.14.1 and 0.30.4 for three hours, tagged latest; roughly 100 million weekly downloads. 29 April: Mini Shai-Hulud hits four SAP-related npm packages. 11 May 19:20 to 19:26 UTC: 84 versions across 42 TanStack packages, then @uipath, @mistralai/mistralai, OpenSearch, Guardrails AI; 172 packages and 403 versions inside 48 hours, ~518M cumulative downloads. 2025 alone: 454,648 malicious npm packages, more than 99 per cent of all open-source malware now targets npm. The architectural answer has been quietly available for decades.

0 inbound links website en
TanStack npm Packages Hit by Mini Shai-Hulud | Snyk

On May 11, 2026, the Mini Shai-Hulud worm compromised 84 npm package artifacts across 42 @tanstack/* packages (as well as @squawk/*, @mistralai/* packages, and others) by chaining a GitHub Actions "Pwn Request," cache poisoning, and OIDC token extraction from runner memory — producing the first npm supply chain attack with valid SLSA Build Level 3 attestations. Here's what happened, what was stolen, and what you need to do right now.

8 inbound links article en developersecuritydevopstecharticlesnyk-open-sourcesnyk-security-intelci-cdscmsbomsupply-chain-securitydevsecopsopen-source-securityvulnerability-insights
Techmeme

Top news and commentary for technology's leaders, from all around the web.