216.73.216.226

Mini Shai-Hulud Hits TanStack npm Packages

· Published 21/05/2026 17:38 · Modified 21/05/2026 16:11

Export JSON

Essential information

Published
21/05/2026 17:38
Modified
21/05/2026 16:11
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
credential theft github actions mini shai-hulud npm oidc token pypi supply chain attack tanstack
Tags
2026-05-21 credential-theft github actions mini shai hulud npm oidc token pypi supply chain attack tanstack
Related entities
1 indicators, 1 observables, 1 intrusion sets (apt), 1 malware, 2 others

Description

The campaign compromised 84 package artifacts in the namespace with credential-stealing malware targeting continuous integration systems. On May 11, 2026, attackers published 84 malicious versions across 42 packages by chaining the pull_request_target pattern, cache poisoning, and extracting OIDC tokens from runner process memory. The attack affected high-profile packages including @/react-router, which receives over 12 million weekly downloads. Wiz attributes this activity to TeamPCP, which has previously compromised SAP, Checkmarx, Bitwarden and other developer tools. The campaign expanded beyond to include OpenSearch versions, mistralai packages, and others, using three exfiltration routes including typosquatted domains, Session messenger network, and GitHub API dead drops.

External references