External Publication
Visit Post

Shai Hulud attack ships signed malicious TanStack, Mistral npm packages

BleepingComputer [Unofficial] May 12, 2026
Source
Hundreds of packages across npm and PyPI have been compromised in a new Shai-Hulud supply-chain campaign delivering credential-stealing malware targeting developers. [...]

Discussion in the ATmosphere

Loading comments...