logo

Hackers have compromised dozens of popular open source packages in an ongoing supply-chain attack

ID: 47aa1a87-1ea7-54db-8a61-746167eb4148

STIX ID: report--47aa1a87-1ea7-54db-8a61-746167eb4148

Feed Name: TechCrunch Security News

Threat Score
85/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Lorenzo Franceschi-Bicchierai

...
...

Security firms report an ongoing supply-chain campaign called “Mini Shai-Hulud” where attackers took over developer accounts and published malicious updates—over 630 malicious versions across 317 open-source packages in ~20 minutes—to steal credentials (including from password managers) and spread malware; affected projects include Antv and the TanStack library, with downstream impacts reaching OpenAI employees.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.