TeamPCP supply chain attack hits TanStack
ID: a2d7074b-c5f3-5177-897b-85b3ceafb269
STIX ID: report--a2d7074b-c5f3-5177-897b-85b3ceafb269
Feed Name: ThreatLocker Blog
On May 11, 2026 attackers published dozens of malicious npm package versions in the TanStack ecosystem and related PyPI packages by chaining a pull_request_target Pwn-Request, GitHub Actions cache poisoning, and extraction of OIDC tokens from runner memory to push credential‑stealing Mini Shai‑Hulud payloads (attributed to TeamPCP); the report provides a technical breakdown, IOCs (file hashes, network hosts, persistence artifacts), and recommended mitigation and remediation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
