Compromised Mistral AI and TanStack packages may have exposed GitHub, cloud and CI/CD credentials in 'mini Shai Hulud' malware infection — supply-chain campaign spreads across npm and AI developer ecosystems like wildfire

TL;DR AI
2 min readKey summary
Malicious versions of Mistral AI and TanStack packages were found in npm and PyPI, as part of a broader Mini Shai-Hulud supply-chain campaign.
The tampered packages could run on install or import, download staged payloads, and steal developer credentials.
Targets included GitHub tokens, cloud API keys, and CI/CD secrets, increasing the blast radius across downstream projects and services.
The incident underscores how trusted developer packages can be weaponized to harvest high-value access and spread malware through software update channels.

