chiprook
← Security
SecurityOctober 1, 2026, 10:46

TanStack npm supply-chain attack: Mini Shai-Hulud worm hit 42 packages

On May 11, 2026, the Mini Shai-Hulud worm published 84 malicious versions of 42 @tanstack/* packages with valid SLSA provenance after reading an OIDC token from runner memory. A Dependabot bump pulled it into the squawk project, which published 110 more versions in 95 minutes; over 160 packages were affected, including Mistral's.

TanStack npm supply-chain attack: Mini Shai-Hulud worm hit 42 packages
#TanStack#Npm#Dependabot#Mistral
Read next
Security

Shai-Hulud npm worm ran code just by opening a folder

Security

MemOS supply-chain worm sckit steals developer tokens

Security

ChainDrop npm Worm Hijacks 444 Packages with 2B Monthly Downloads

Security

Shai-Hulud attack steals 170 private CrowdSec repositories