logo

Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised

ID: ac7f5a87-f3ce-57c2-a3da-161b423111f4

STIX ID: report--ac7f5a87-f3ce-57c2-a3da-161b423111f4

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Rami McCarthy

...
...

On 11 May 2026, a supply-chain campaign attributed to TeamPCP compromised multiple npm and PyPI packages (notably @tanstack/react-router, many @tanstack packages, multiple @uipath packages, mistralai, guardrails-ai) by exploiting GitHub Actions and poisoned caches to publish trojanized releases; the payloads are credential stealers and self-propagating worms that exfiltrate secrets via a typosquat domain, the Session messenger network, and GitHub dead drops, include a persistent gh-token-monitor wiper, and contain numerous IoCs (file hashes, C2 domain git-tanstack.com, Session seeds, and C2 IP 83.142.209.194).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.