Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
Tue May 12 2026
Development
Malware
Open Source
www.bleepingcomputer.com
Hundreds of packages across npm and PyPI have been compromised in a new Shai-Hulud supply-chain campaign delivering credential-stealing malware targeting developers. [...]