GeistHaus
log in · sign up

Postmortem: TanStack npm supply-chain compromise | TanStack Blog

tanstack.com

On 2026-05-11, an attacker chained a pull_request_target Pwn Request, GitHub Actions cache poisoning across the fork↔base trust boundary, and OIDC token extraction from runner memory to publish 84 malicious versions across 42 @tanstack/* packages on npm. Full postmortem.

31 pages link to this URL
Supply chain attacks in the AI era: the state of open source in 2026

In 18 months, npm, PyPI, RubyGems, Maven and Crates have all shipped malware. AI is accelerating both sides of the playbook. A tour of what's happening, with the defensive baseline at the end.

0 inbound links article en Tech supply chain attack 2026npm pnpm minimumReleaseAgeShai-Hulud wormtj-actions changed-files CVE-2025-30066slopsquattingaxios npm compromise 2026Bitwarden CLI malicious 2026.4.0TanStack npm postmortemPyPI Trusted Publishingopen source security 2026
‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack

A sprawling supply-chain attack dubbed "Mini Shai-Hulud" has compromised hundreds of open-source packages, including TanStack and MistralAI. By hijacking automated CI/CD pipelines and spoofing digital signatures, the TeamPCP-linked malware successfully bypassed 2FA to steal cloud credentials and extort developers across major registries.

1 inbound link article en AI aikido securityartificial intelligence (ai)ci/cdmini shai huludnpmopen source softwareshai huludsnyksocketsupply chain
OpenAI hit by supply chain attack linked to malicious TanStack packages

OpenAI said the TanStack supply chain attack compromised two employee devices and exposed credentials from code repositories.

0 inbound links article en Breaking NewsCyber CrimeHackingSecurity CybercrimeHackinghacking newsinformation security newsIT Information SecuritymalwareMini Shai-HuludOpenAIPierluigi PaganiniSecurity AffairsSecurity Newssupply chain attack
CTO at NCSC Summary: week ending May 17th

My Ministers will also introduce legislation to improve the country’s defences against cyber-security threats [Cyber Security and Resilience Bill].

0 inbound links article en
TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages - StepSecurity

The Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. StepSecurity's OSS Package Security Feed first detected the attack in official @tanstack packages and is tracking its spread across the ecosystem in real time.

0 inbound links website en
TanStack npm Packages Hit by Mini Shai-Hulud | Snyk

On May 11, 2026, the Mini Shai-Hulud worm compromised 84 npm package artifacts across 42 @tanstack/* packages (as well as @squawk/*, @mistralai/* packages, and others) by chaining a GitHub Actions "Pwn Request," cache poisoning, and OIDC token extraction from runner memory — producing the first npm supply chain attack with valid SLSA Build Level 3 attestations. Here's what happened, what was stolen, and what you need to do right now.

8 inbound links article en developersecuritydevopstecharticlesnyk-open-sourcesnyk-security-intelci-cdscmsbomsupply-chain-securitydevsecopsopen-source-securityvulnerability-insights
TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages - StepSecurity

The Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. StepSecurity's OSS Package Security Feed first detected the attack in official @tanstack packages and is tracking its spread across the ecosystem in real time.

19 inbound links website en
Techmeme

Top news and commentary for technology's leaders, from all around the web.