Mini Shai-Hulud Hits TanStack npm Packages

2026-05-12T14:52:16Zea16cdf97429066d840cf4c69395bd4bddfe99203c7de03cbd6ba5886582888a
ai-assisted-exploitationandroidcisacritical-infrastructuredata-breachinfostealerkernel-vulnerabilitylinuxmobile-malwarencscnpmphishingpypiransomwareregulatory-finesupply-chainthreat-actor-activitytrojanzero-day

What happened

A wide-ranging set of incidents and research highlights: supply‑chain compromises and malware distribution (Mini Shai‑Hulud affecting TanStack npm and PyPI, trojanized Daemon Tools, fake Claude sites/installers pushing PowerShell stealers, Beagle backdoor, DonutLoader); multiple infostealer and RAT campaigns (ClickFix delivering Vidar, CloudZ/Pheno abusing Phone Link, Deep#Door Python RAT, TrickMo routing Android C2 via TON); large-scale phishing and extortion activity (mass compliance-phishing, ShinyHunters Canvas campaign, SSA‑style Venomous#Helper); high‑impact vulnerabilities and zero‑day/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
ea16cdf97429066d840cf4c69395bd4bddfe99203c7de03cbd6ba5886582888a
Enrichment time
2026-05-12T14:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.