Switch language한국어
Back to the list

Compromised Mistral AI and TanStack packages may have exposed GitHub, cloud and CI/CD credentials in 'mini Shai Hulud' malware infection — supply-chain campaign spreads across npm and AI developer ecosystems like wildfire

TL;DR AI

Key summary

2 min read
  1. Malicious versions of Mistral AI and TanStack packages were found in npm and PyPI, as part of a broader Mini Shai-Hulud supply-chain campaign.

  2. The tampered packages could run on install or import, download staged payloads, and steal developer credentials.

  3. Targets included GitHub tokens, cloud API keys, and CI/CD secrets, increasing the blast radius across downstream projects and services.

  4. The incident underscores how trusted developer packages can be weaponized to harvest high-value access and spread malware through software update channels.

Read the original