Mini Shai-Hulud: a supply chain worm that exploited TanStack and the npm ecosystem

TL;DR AI
2 min readKey summary
Mini Shai-Hulud is a critical supply-chain worm that compromised hundreds of npm and PyPI packages.
Attackers started with popular packages like TanStack, then used compromised GitHub Actions and OIDC flows to publish fake releases and steal secrets.
The malware auto-propagated through maintainer-owned packages, turning trusted CI/CD and publishing pipelines into an attack vector.
The campaign highlights how short-lived identity tokens and trusted build systems can be abused for rapid cross-ecosystem spread and credential theft.
