CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1283

As cited

Copy frozen at (site build).

threat intel

Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised

Malicious npm packages linked to the Mini Shai-Hulud supply chain campaign have compromised TanStack and additional developer tooling packages. The attack targets high-value dependencies that could expose downstream projects to compromise through software supply chain pollution.

Why it matters: Development teams relying on affected npm packages face immediate risk of code injection and malware distribution to their applications and users; practitioners should audit dependencies and update to verified clean versions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary