logo

TeamPCP supply chain attack hits TanStack

ID: a2d7074b-c5f3-5177-897b-85b3ceafb269

STIX ID: report--a2d7074b-c5f3-5177-897b-85b3ceafb269

Feed Name: ThreatLocker Blog

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

...
...

On May 11, 2026 attackers published dozens of malicious npm package versions in the TanStack ecosystem and related PyPI packages by chaining a pull_request_target Pwn-Request, GitHub Actions cache poisoning, and extraction of OIDC tokens from runner memory to push credential‑stealing Mini Shai‑Hulud payloads (attributed to TeamPCP); the report provides a technical breakdown, IOCs (file hashes, network hosts, persistence artifacts), and recommended mitigation and remediation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.