TanStack Was Not the Whole Story: Mini Shai-Hulud Was an npm/PyPI Supply-Chain Worm

TanStack Was Not the Whole Story: Mini Shai-Hulud Was an npm/PyPI Supply-Chain Worm

This article is based on public reporting available as of 2026-05-13. Mini Shai-Hulud is still an actively tracked campaign, so affected packages and IOCs (indicators of compromise) may change. In May 2026, a supply-chain compromise was reported across TanStack's npm packages. Malicious versions were published for 42 @tanstack/* packages, and installing those versions triggered a credential stealer. If you look only at TanStack, the incident can seem like a single npm compromise. But when you...

Original Source

Read the full article at Dev →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.