MEDIUMSupply Chain
Global

Shai Hulud attack ships signed malicious TanStack, Mistral npm packages

·Source: BleepingComputer

Updated:

Executive Summary

Hundreds of packages across npm and PyPI have been compromised in a new Shai-Hulud supply-chain campaign delivering credential-stealing malware targeting developers. [...]

Analysis

Hundreds of packages across npm and PyPI have been compromised in a new Shai-Hulud supply-chain campaign delivering credential-stealing malware targeting developers. [...]
Source Attribution

Originally published by BleepingComputer on May 12, 2026.

Related Threats