TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack
CYBERSECURITY FEATURED ANALYSIS

TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack

SOURCE

Blog RSS Feed | Snyk

DATE

READ

1 min read

On May 11, 2026, the Mini Shai-Hulud worm compromised 84 npm package artifacts across 42 @tanstack/* packages (as well as @squawk/, @mistralai/ packages, and others) by chaining a GitHub Actions “Pwn …

On May 11, 2026, the Mini Shai-Hulud worm compromised 84 npm package artifacts across 42 @tanstack/* packages (as well as @squawk/, @mistralai/ packages, and others) by chaining a GitHub Actions “Pwn Request,” cache poisoning, and OIDC token extraction from runner memory — producing the first npm supply chain attack with valid SLSA Build Level 3 attestations. Here’s what happened, what was stolen, and what you need to do right now.