Supply Chain Incident
Mini Shai-Hulud TanStack npm and PyPI supply-chain wave
Mini Shai-Hulud compromised TanStack release automation and spread across npm and PyPI packages through trusted publishing, cache poisoning, and credential theft from CI/CD environments.
Affected Packages
Affected Releases
No structured records.
Repositories
Organizations
Maintainers
No structured records.
Threat Actors
Campaigns
Build Systems
- GitHub Actions
Distribution Channels
- GitHub Actions workflow
- npm registry
- PyPI
Compromised Accounts
- GitHub Actions OIDC publishing identity
- stolen npm and GitHub credentials
Connected Entities
- @tanstack/react-routerPackage
- GitHub ActionsBuild System
- GitHub Actions OIDC publishing identityCompromised Account
- GitHub Actions workflowDistribution Channel
- Guardrails AIOrganization
- guardrails-aiPackage
- Mistral AIOrganization
- mistralaiPackage
- npm registryDistribution Channel
- PyPIDistribution Channel
- stolen npm and GitHub credentialsCompromised Account
- TanStackOrganization
- TanStack/routerRepository
- TeamPCPThreat Actor
- TeamPCP Multi-Ecosystem Supply Chain CampaignCampaign
Attribution Evidence
Socket and StepSecurity connect the Mini Shai-Hulud activity to TeamPCP-style worm behavior and infrastructure; Threatpedia preserves the vendor-assessed attribution level.
The Mini Shai-Hulud TanStack event is modeled as part of the broader TeamPCP multi-ecosystem supply-chain campaign.
References
- TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain AttackSocket Research Team · 2026-05-11
- TanStack npm supply chain compromise postmortemTanStack · 2026-05-11
- Mini Shai-Hulud is back: A self-spreading supply chain attack hits the npm ecosystemStepSecurity · 2026-05-11
- Our response to the TanStack npm supply chain attackOpenAI · 2026-05-13
- TanStack npm packages hit by Mini Shai-HuludSnyk · 2026-05-12