Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
ID: 954feb32-b250-56c0-8702-a8bcc60a3133
STIX ID: report--954feb32-b250-56c0-8702-a8bcc60a3133
Feed Name: The Hacker News
TeamPCP's 'Mini Shai-Hulud' supply-chain campaign has injected malicious code into multiple npm and PyPI packages (including TanStack, UiPath, Mistral AI, OpenSearch, Guardrails AI) to deliver an obfuscated credential stealer that targets cloud providers, wallets, CI systems, AI tools, and messaging apps; it exfiltrates data to a Session Protocol domain and via stolen GitHub tokens, abuses GitHub Actions/OIDC and cache poisoning to publish malicious versions with valid SLSA attestations, establishes persistence in developer IDEs, and has been assigned CVE-2026-45321 (CVSS 9.6).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
