An attacker published 84 malicious npm artifacts across 42 @tanstack/* packages, using TanStack’s legitimate GitHub Actions OIDC trusted-publisher path to push poisoned releases to the npm registry. TanStack said the intrusion chained a pull_request_target “Pwn Request” misconfiguration, GitHub Actions cache poisoning across the fork-to-base trust boundary, and runtime extraction of an OIDC token from the Actions runner process, allowing the attacker to publish under a trusted identity rather than altering the release workflow itself. Each impacted package received two malicious versions during a brief publication window, and the compromised releases were later deprecated and removed with help from npm security.
The malicious packages installed an optional dependency that fetched attacker-controlled code and executed it through a prepare lifecycle hook, launching heavily obfuscated JavaScript designed to steal credentials from developer and CI environments. Reports say the payload searched for AWS, GCP, Azure, Kubernetes, GitHub, SSH, and npm secrets, including .npmrc contents, cloud credentials, GitHub tokens, and SSH keys, then exfiltrated the data over the encrypted Session/Oxen messenger network while masking activity behind an intentional install failure. TanStack purged GitHub Actions caches and hardened workflows, and users who installed affected versions were urged to treat affected hosts as compromised and rotate credentials immediately.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
OpenAI said two employees’ devices were affected through the earlier TanStack supply-chain attack, resulting in unauthorized access to a limited subset of internal source code repositories and theft of limited credential material. The company said it found no evidence of impact to user data, production systems, intellectual property, or software integrity, and began rotating product-signing certificates as a precaution.
On 2026-05-12, Netskope reported additional technical details on the TanStack-linked npm worm, including use of a Bun-based drop-and-execute chain, theft of GitHub credentials via gh auth token, and communication with the lookalike domain git-tanstack.com. The report also said the malware targeted AWS environments by querying instance metadata and interacting with STS and SSM endpoints to expand access using exposed instance-role credentials.
On 2026-05-12, Aikido and Socket Threat Research reported that the Mini Shai-Hulud campaign had grown beyond the initial TanStack disclosures, with Aikido identifying 373 malicious package-version entries across 169 npm package names. The researchers said the worm-like campaign was ongoing and spreading through compromised maintainer accounts and trusted publishing workflows across multiple organizations and ecosystems.
On 2026-05-12, reporting tied the TanStack npm compromise to a wider 'Mini Shai-Hulud' software supply-chain campaign attributed to TeamPCP. The campaign reportedly also involved malicious npm and PyPI packages associated with organizations and projects including Mistral AI, UiPath, OpenSearch, and Guardrails AI.
TanStack's postmortem said the intrusion combined a pull_request_target 'Pwn Request' misconfiguration, cache poisoning across the fork-to-base trust boundary, and runtime extraction of an OIDC token from the GitHub Actions runner process. This explained how the attacker obtained trusted publishing capability for the malicious npm releases.
After the compromise, TanStack deprecated all affected package versions, worked with npm security to remove the malicious tarballs, purged GitHub Actions caches, and hardened workflows. Users who installed impacted packages during the exposure window were advised to treat affected hosts as compromised and rotate credentials immediately.
On 2026-05-11, Snyk reported that the TanStack-linked Mini Shai-Hulud malware could establish persistence through Claude Code and VS Code hooks. The report warned incident responders to remove persistence mechanisms before rotating credentials to avoid triggering a destructive dead-man’s switch.
The compromised package versions delivered an obfuscated credential-stealing payload during installation, including via a malicious optional dependency and prepare hook. The malware searched for and exfiltrated cloud credentials, GitHub tokens, SSH keys, .npmrc contents, Kubernetes and other secrets, with reporting indicating exfiltration through the Session/Oxen messenger network.
StepSecurity reported that the malicious TanStack npm releases were published through legitimate GitHub Actions trusted publishing and were accompanied by valid SLSA Build Level 3 provenance attestations. The finding showed that signed provenance and attestations did not prevent the attacker from distributing poisoned artifacts once the release chain was hijacked.
On 2026-05-11, an attacker published 84 malicious versions across 42 @tanstack/* packages to the npm registry within a short window of roughly 19:20 to 19:26 UTC. The poisoned releases were published via TanStack's legitimate GitHub Actions OIDC trusted-publisher path, indicating abuse of the release chain rather than direct workflow modification.
On 2026-04-29, an earlier SAP-related Shai-Hulud supply-chain wave occurred before the TanStack compromise. Endor Labs describes the May 11 TanStack incident as a technical escalation of that prior campaign, indicating the attackers had already been conducting related package-poisoning activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
21 references tracked. Mallory keeps watching after this page renders.
techcrunch.com
Open sourcenetskope.com
Open sourceinfosecurity-magazine.com
Open sourcecybersecuritynews.com
Open sourcegithub.com
Open sourceopennet.me
Open sourceapp.stepsecurity.io
Open sourceapp.stepsecurity.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.