Switch language한국어
Back to the list

Mini Shai-Hulud: a supply chain worm that exploited TanStack and the npm ecosystem

TL;DR AI

Key summary

2 min read
  1. Mini Shai-Hulud is a critical supply-chain worm that compromised hundreds of npm and PyPI packages.

  2. Attackers started with popular packages like TanStack, then used compromised GitHub Actions and OIDC flows to publish fake releases and steal secrets.

  3. The malware auto-propagated through maintainer-owned packages, turning trusted CI/CD and publishing pipelines into an attack vector.

  4. The campaign highlights how short-lived identity tokens and trusted build systems can be abused for rapid cross-ecosystem spread and credential theft.

Read the original