Mini Shai-Hulud Hits TanStack npm Packages
ID: 500e74aa-9a8c-5d0c-bec6-94d7249cb88f
STIX ID: report--500e74aa-9a8c-5d0c-bec6-94d7249cb88f
Feed Name: Infosecurity Magazine (News)
A widespread supply-chain campaign (Mini Shai‑Hulud, attributed to TeamPCP) hijacked legitimate release pipelines to publish 84 malicious npm package versions across 42 @tanstack/* packages on May 11, 2026, and later affected other npm and PyPI artifacts; the payloads are credential-stealing/daemonizing malware targeting CI systems (GitHub Actions OIDC, GitLab, CircleCI) with multiple exfiltration channels and destructive capabilities, and the advisory recommends rotating credentials and reviewing cloud logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
