logo

Mini Shai-Hulud Is Back: 172 npm and PyPI Packages Compromised in Latest Wave

ID: 8f2e94fc-2693-5d19-a988-ed8bf7f0be01

STIX ID: report--8f2e94fc-2693-5d19-a988-ed8bf7f0be01

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Tom Abai

...
...

Mend reports that the Mini Shai-Hulud supply-chain campaign resurfaced on May 11–12, 2026, compromising 172 unique npm and PyPI packages (403 malicious versions) including prominent scopes like @tanstack and @uipath; compromised packages execute a preinstall hook to download a Bun runtime and run an obfuscated ~11.7 MB JavaScript credential stealer that exfiltrates SSH keys, cloud credentials, npm/GitHub tokens, CI environment variables and AI tool configs. The adversary uses stolen npm tokens to identify publishable packages, inject malicious dependencies, bump versions, and automatically publish compromised releases; Mend issued three MSC advisories covering the affected packages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.