Corpus graph previewActor to Incident
Supply Chain GraphPan, zoom, and select actor, campaign, and incident tiers.

Supply Chain graph is loading. Keyboard controls become available after graph initialization.

Supply Chain Incident

Focused Graph View

The persistent graph is framed to this incident while the canonical page heading and details continue below.

270 nodes467 edgesCold links hydrate here

Supply Chain Incident

Mini Shai-Hulud TanStack npm and PyPI supply-chain wave

Mini Shai-Hulud compromised TanStack release automation and spread across npm and PyPI packages through trusted publishing, cache poisoning, and credential theft from CI/CD environments.

ConfidenceHigh
Evidence LevelVendor
Attack StagePackage Publish
Source Artifact DivergenceNo
Attribution ConfidenceLikely

Affected Packages

Affected Releases

No structured records.

Repositories

Organizations

Maintainers

No structured records.

Threat Actors

Campaigns

Build Systems

  • GitHub Actions

Distribution Channels

  • GitHub Actions workflow
  • npm registry
  • PyPI

Compromised Accounts

  • GitHub Actions OIDC publishing identity
  • stolen npm and GitHub credentials

Connected Entities

Attribution Evidence

References