logo

Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages

ID: 954feb32-b250-56c0-8702-a8bcc60a3133

STIX ID: report--954feb32-b250-56c0-8702-a8bcc60a3133

Feed Name: The Hacker News

Threat Score
92/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: [email protected] (The Hacker News)

...
...

TeamPCP's 'Mini Shai-Hulud' supply-chain campaign has injected malicious code into multiple npm and PyPI packages (including TanStack, UiPath, Mistral AI, OpenSearch, Guardrails AI) to deliver an obfuscated credential stealer that targets cloud providers, wallets, CI systems, AI tools, and messaging apps; it exfiltrates data to a Session Protocol domain and via stolen GitHub tokens, abuses GitHub Actions/OIDC and cache poisoning to publish malicious versions with valid SLSA attestations, establishes persistence in developer IDEs, and has been assigned CVE-2026-45321 (CVSS 9.6).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.