TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages
The Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. The attack was first detected by StepSecurity in official @tanstack packages and is spreading across the npm ecosystem in real time.
- Disclosed
- Last updated
- Blast radius
- Multiple npm packages in the TanStack ecosystem and potentially spreading across npm
- Attack vectors
- Threat actor
- Affected entities
- @tanstackOfficial TanStack npm packages compromised
StepSecurity has detected an active supply chain attack using the Mini Shai-Hulud worm targeting the npm ecosystem. The malicious campaign compromises legitimate npm packages by hijacking their CI/CD pipelines and exfiltrating developer credentials and secrets.\n\nThe attack was first identified in official @tanstack packages. The worm appears to be self-spreading, capable of moving from one compromised package to others across the npm ecosystem.\n\nStepSecurity's OSS Package Security Feed is actively tracking the spread of this attack in real time, indicating the incident remains ongoing with potential for further compromises.
Indicators of compromise
- Packages
- @tanstack
Remediation
- Identify and audit all CI/CD pipeline configurations for the affected @tanstack packages and any packages that depend on them
- Rotate all developer credentials and secrets that may have been exposed
- Review npm account access logs and implement additional authentication controls (e.g., 2FA) for npm accounts
- Scan build systems and deployment infrastructure for signs of compromise or injected malicious code
- Subscribe to StepSecurity's OSS Package Security Feed for ongoing alerts about this campaign
- Audit package dependencies for compromised versions and update to clean releases
Sources
Cite this entry
"TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed May 12, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/teampcp-s-mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-compromis-19lamt
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedhigh
M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions
M-Red-Team compromised AsyncAPI npm packages via GitHub Actions, injecting malicious code into the supply chain. The attack leveraged build system access to distribute compromised packages to downstream consumers.
M Red TeamnpmOtherCompromised packageBuild-system compromise - activecritical
Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope
The Shai-Hulud worm has hijacked intercom-client@7.0.4 (361,510 weekly downloads) via a compromised GitHub Actions OIDC publishing pipeline, 29 hours after compromising mbt@1.2.48 and @cap-js/sqlite@2.2.2. The worm is actively propagating through CI/CD infrastructure stolen from earlier victims, targeting multi-cloud credentials (AWS, GCP, Azure).
Shai-HuludnpmOtherCompromised packageBuild-system compromiseAccount takeover - containedcritical
Malicious code in jest-canvas-mock (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including jest-canvas-mock, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in mcp-mermaid (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including mcp-mermaid, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit