A large software supply-chain campaign dubbed Mini Shai-Hulud compromised more than 170 npm packages and at least two PyPI packages tied to projects including TanStack, Mistral AI, OpenSearch, UiPath, Guardrails AI, and others. Researchers and vendors attributed the activity to TeamPCP, saying the attackers abused GitHub Actions release workflows—especially pull_request_target, cache poisoning, and theft of short-lived OIDC material from runners—to publish trojanized packages with apparently legitimate SLSA provenance, Sigstore attestations, and trusted-publishing signatures. Reports variously counted between roughly 160 and 400+ malicious package versions, with some affected packages totaling hundreds of millions of downloads, and OpenSearch and Mistral both confirmed compromised releases while TanStack described a chained workflow attack on its publishing pipeline.
The malware targeted developer workstations and CI/CD systems, stealing npm, GitHub, cloud, Kubernetes, Vault, SSH, Docker, and AI-tool credentials, then attempting worm-like propagation by republishing infected packages with stolen tokens or workflow-issued publish credentials. Investigators said the payload also established persistence through VS Code tasks, Claude Code hooks, and in some cases system services, while exfiltrating data through Session, GitHub dead drops, and other attacker infrastructure; some variants included extortion notes, dead-man-switch logic, and geofenced destructive behavior. Defenders were urged to treat hosts that installed affected versions as potentially fully compromised, remove persistence before revoking tokens where applicable, rotate all exposed secrets from clean systems, invalidate CI caches, audit lockfiles and publishing activity, and rebuild impacted environments from trusted sources.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
21 events from the most recent confirmed update back to the earliest known activity.
A report said a software supply-chain attack had compromised at least nine npm packages under the CrowdStrike scope as part of a broader wave linked to the earlier Tinycolor npm compromise. The post said the known affected package count had grown from about 40 to roughly 180 packages and described credential theft with exfiltration via webhook.site.
On 2026-06-08, attackers using a compromised maintainer account force-pushed a Shai-Hulud-related credential-stealing payload to the main branch of Pythagora-io/gpt-pilot. StepSecurity reported the malicious changes failed to propagate through CI because ruff formatting and linting checks caught violations, but the incident exposed the lack of branch protection and the attacker’s attempt to deploy a loader and obfuscated JavaScript stealer.
Researchers reported that dozens of Microsoft-associated open source packages were compromised late the previous week and modified to include the Miasma credential stealer, which activated in AI coding agents. The reference says GitHub flagged 73 packages as malicious and blocked them, while Microsoft temporarily removed some repositories during its investigation.
Socket Threat Research reported 23 newly identified malicious artifacts tied to the broader Mini Shai-Hulud, Miasma, and Hades supply-chain campaign, bringing its tracker to 471 affected artifacts across npm and PyPI. The report also disclosed additional delivery mechanisms, including trojanized .abi3.so extensions, a langchain-core-mcp variant that executes a separate _index.js payload with Bun, and an anti-analysis fake prompt-injection comment embedded in the stealer.
Socket researchers reported a new 'Hades' campaign on PyPI involving 37 malicious wheels across 19 packages. The wave used Python .pth startup files and Bun to launch an obfuscated JavaScript credential stealer, and some affected releases were quarantined by PyPI while others were reported to the security team.
A SLSA blog post published on May 15, 2026 described how attackers chained a GitHub Actions pull_request_target misconfiguration, pnpm cache poisoning, and OIDC token extraction from runner memory to publish malicious packages through legitimate CI/CD pipelines. The analysis said the malicious packages still carried valid npm/Sigstore provenance attestations, showing that provenance alone did not protect against compromise without stronger SLSA Build Level 3 isolation guarantees.
Hunt.io published analysis of the second-stage Python toolkit used in the campaign, describing a hardcoded primary C2, a GitHub commit-message dead-drop fallback, and exfiltration through repositories created under victims' own GitHub accounts. The report also documented anti-analysis checks, systemd persistence, modular credential theft, and a geofenced wiper component.
As part of its response, OpenAI said macOS users must update their OpenAI applications by June 12 to continue receiving updates and support. The notice accompanied the company's disclosure of limited impact from the TanStack-linked supply-chain incident.
OpenAI disclosed that the broader supply-chain campaign affected two employee devices, corrupted software signing keys, and led to limited unauthorized access and credential-focused exfiltration from a small subset of internal source code repositories. The company said no customer data was stolen and no published software was modified.
Following the compromise, OpenSearch said it blocked write permissions on project repositories until credentials could be rotated. The advisory estimated rotation would be completed by May 13, 2026.
Reporting states the broader Mini Shai-Hulud supply-chain activity began with SAP-related packages in April before later expanding into other ecosystems.
A public Bash audit script dated 2026-05-12 was created to scan systems for indicators tied to the Mini Shai-Hulud/TanStack/Mistral compromise cluster. It checks for malicious files, persistence mechanisms, network indicators, and dependency exposure across npm and PyPI artifacts.
Mistral published a security advisory stating that investigation pointed to an affected developer device and that there was no indication its infrastructure was compromised. It also assessed that the embedded dropper in the malicious npm packages failed to execute because setup.mjs referenced a non-existent tanstack_runner.js file.
SafeDep reported the incident on May 12, 2026, characterizing it as a coordinated malware-related supply-chain attack affecting more than 400 npm package versions and at least two PyPI packages. The report identified impacted ecosystems including TanStack, Mistral AI, UiPath, OpenSearch, and guardrails-ai.
An OpenSearch advisory said all four malicious @opensearch-project/opensearch versions were published on 2026-05-12 UTC and that any computer installing or updating to them between 00:00 UTC and 10:00 UTC should be treated as fully compromised. The project recommended immediate containment and secret rotation.
Mistral later disclosed that three npm packages—@mistralai/mistralai, @mistralai/mistralai-azure, and @mistralai/mistralai-gcp—were compromised and available on npm between May 11 at 22:45 UTC and May 12 at 01:53 UTC. The company said the malicious releases were subsequently removed.
OpenSearch said the malicious prerelease packages were removed from npm by 11:00 p.m. EDT on May 11, 2026. The project warned that systems installing or executing them during the exposure window should be treated as potentially fully compromised.
OpenSearch disclosed a critical compromise of its npm publishing infrastructure as part of the broader campaign. Attackers used compromised credentials tied to the JavaScript client repository to publish malicious prerelease versions 3.5.3, 3.6.2, 3.7.0, and 3.8.0.
A GitHub issue reported that the @mistralai/mistralai npm package appeared to be compromised and linked it to the latest Shai Hulud worm activity. The post specifically pointed to version 2.2.4 and external reporting on the campaign.
On May 11, 2026, TeamPCP began a coordinated software supply-chain attack across npm and PyPI, initially hitting packages in the @tanstack namespace before expanding to other publishers. Multiple reports describe the wave as using trusted publishing workflows and GitHub Actions weaknesses to release trojanized packages.
Checkmarx confirmed that tampered Jenkins AST plugin version 2026.5.09 was published to the Jenkins Marketplace between 2026-05-09 and 2026-05-10. The company said the compromise affected several hundred Jenkins controllers and marked its third compromise in three months.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
35 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcelinuxsecurity.com
Open sourcearstechnica.com
Open sourcestepsecurity.io
Open sourcethreats.wiz.io
Open sourcegithub.com
Open sourcelinkedin.com
Open sourcedigital.nhs.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.