Mini Shai-Hulud Is Back: 172 npm and PyPI Packages Compromised in Latest Wave
ID: 8f2e94fc-2693-5d19-a988-ed8bf7f0be01
STIX ID: report--8f2e94fc-2693-5d19-a988-ed8bf7f0be01
Feed Name: Security Boulevard
Mend reports that the Mini Shai-Hulud supply-chain campaign resurfaced on May 11–12, 2026, compromising 172 unique npm and PyPI packages (403 malicious versions) including prominent scopes like @tanstack and @uipath; compromised packages execute a preinstall hook to download a Bun runtime and run an obfuscated ~11.7 MB JavaScript credential stealer that exfiltrates SSH keys, cloud credentials, npm/GitHub tokens, CI environment variables and AI tool configs. The adversary uses stolen npm tokens to identify publishable packages, inject malicious dependencies, bump versions, and automatically publish compromised releases; Mend issued three MSC advisories covering the affected packages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
