logo

Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack

ID: 6827da93-ad74-518c-ad1c-5febbdeb550e

STIX ID: report--6827da93-ad74-518c-ad1c-5febbdeb550e

Feed Name: Aikido Security's Blog

Threat Score
88/100

Date Published: 2026-05-11

Date Updated: 2026-07-24

...
...

Mini Shai-Hulud is an active npm supply-chain campaign that injected Bun-based infostealer payloads into hundreds of package versions across many namespaces (notably @tanstack, @squawk, @uipath and several unscoped packages). The malware executes during install via lifecycle scripts and Git-hosted optional dependencies to steal GitHub, npm, cloud, and Vault credentials, then abuses CI/OIDC publishing paths to repack and publish further compromised releases; the report includes affected package/version lists, file hashes, network IOCs, detection steps, and remediation advice (rotate secrets, audit publishes, scan lockfiles).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.