Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
2026-05-12T13:23:33Z•d961e8aa72be3f8c37e30bd89396e532a41d03c4479df047cc8ff152ae5cb1e5
CanvasCheckmarxGhostLockHugging FaceInstructureJDownloaderJenkinsMistralPyPISAPShai-HuludShinyHuntersTONTanStackTrickMoWindows APIcredential‑stealerinfostealermac malwaremalvertisingmalwarenpmpatchessupply-chainthreat intelligence
What happened
Multiple active supply-chain and distribution compromises and high-impact security stories: a Shai-Hulud campaign has compromised hundreds of npm and PyPI packages (including signed malicious TanStack and Mistral packages) to deliver credential‑stealing malware targeting developers; a rogue Checkmarx Jenkins plugin and fake Hugging Face/OpenAI repos pushed infostealers; the JDownloader site was altered to distribute a Python RAT; malvertising (via Google Ads and Claude.ai) is pushing Mac malware; Instructure/Canvas was exploited and negotiations with ShinyHunters followed; SAP released May 202
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- d961e8aa72be3f8c37e30bd89396e532a41d03c4479df047cc8ff152ae5cb1e5
- Enrichment time
- 2026-05-12T13:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.