Shai Hulud attack ships signed malicious TanStack, Mistral npm packages

2026-05-12T13:23:33Zd961e8aa72be3f8c37e30bd89396e532a41d03c4479df047cc8ff152ae5cb1e5
CanvasCheckmarxGhostLockHugging FaceInstructureJDownloaderJenkinsMistralPyPISAPShai-HuludShinyHuntersTONTanStackTrickMoWindows APIcredential‑stealerinfostealermac malwaremalvertisingmalwarenpmpatchessupply-chainthreat intelligence

What happened

Multiple active supply-chain and distribution compromises and high-impact security stories: a Shai-Hulud campaign has compromised hundreds of npm and PyPI packages (including signed malicious TanStack and Mistral packages) to deliver credential‑stealing malware targeting developers; a rogue Checkmarx Jenkins plugin and fake Hugging Face/OpenAI repos pushed infostealers; the JDownloader site was altered to distribute a Python RAT; malvertising (via Google Ads and Claude.ai) is pushing Mac malware; Instructure/Canvas was exploited and negotiations with ShinyHunters followed; SAP released May 202

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
d961e8aa72be3f8c37e30bd89396e532a41d03c4479df047cc8ff152ae5cb1e5
Enrichment time
2026-05-12T13:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Shai Hulud attack ships signed malicious TanStack, Mistral npm packages · Baitaphish