TanStack Was Not the Whole Story: Mini Shai-Hulud Was an npm/PyPI Supply-Chain Worm
This article is based on public reporting available as of 2026-05-13. Mini Shai-Hulud is still an actively tracked campaign, so affected packages and IOCs (indicators of compromise) may change. In May 2026, a supply-chain compromise was reported across TanStack's npm packages. Malicious versions were published for 42 @tanstack/* packages, and installing those versions triggered a credential stealer. If you look only at TanStack, the incident can seem like a single npm compromise. But when you...
Original Source
Read the full article at Dev →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.