logo

Shai Hulud attack ships signed malicious TanStack, Mistral npm packages

ID: 8e7e81af-9c68-5c81-b1bd-d64c86d77d15

STIX ID: report--8e7e81af-9c68-5c81-b1bd-d64c86d77d15

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Bill Toulas

...
...

A supply‑chain campaign named Shai‑Hulud, attributed to TeamPCP, has compromised hundreds of npm and PyPI packages (including TanStack and Mistral AI) by stealing CI/OIDC credentials and publishing malicious package versions signed with valid SLSA attestations; the delivered payload is a credential‑stealing infostealer that persists in developer IDEs, exfiltrates secrets over a P2P network, and includes destructive/geofenced behavior, prompting wide credential rotation, audits for persistence, and blocking of known C2 infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.