Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised
ID: ac7f5a87-f3ce-57c2-a3da-161b423111f4
STIX ID: report--ac7f5a87-f3ce-57c2-a3da-161b423111f4
Feed Name: Wiz Blog
On 11 May 2026, a supply-chain campaign attributed to TeamPCP compromised multiple npm and PyPI packages (notably @tanstack/react-router, many @tanstack packages, multiple @uipath packages, mistralai, guardrails-ai) by exploiting GitHub Actions and poisoned caches to publish trojanized releases; the payloads are credential stealers and self-propagating worms that exfiltrate secrets via a typosquat domain, the Session messenger network, and GitHub dead drops, include a persistent gh-token-monitor wiper, and contain numerous IoCs (file hashes, C2 domain git-tanstack.com, Session seeds, and C2 IP 83.142.209.194).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
