Malicious node-ipc versions published to npm in suspected maintainer account compromise
2026-05-15T20:52:04Z•a75445d3591bb96670de29a074ed9e361497d0f22b60e4ffdcd551b5d284766a
@tanstackBunCVE-2026-40478GitHub ActionsMini Shai-HuludOIDC token extractionPwn RequestPyPISLSA level 3Thymeleafcache poisoningcredential stealermaintainer account compromisenode-ipcnpmpackage compromisepatchingrotate secretssupply chaintemplate injection
What happened
Multiple high-impact supply-chain compromises and malicious package releases were reported in May 2026: malicious node-ipc versions were published to npm (suspected maintainer account compromise), 84 @tanstack/* npm artifacts were compromised by the “Mini Shai-Hulud” attack chain (GitHub Actions "Pwn Request", cache poisoning, and OIDC token extraction producing builds with valid SLSA Level 3 attestations), and a PyPI release of lightning contained a Bun-based credential stealer that runs on import. Separately, Thymeleaf template injection (CVE-2026-40478, CVSS 9.1) affects Thymeleaf < 3.1.4;
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- snyk_blog
- Record identifier
- a75445d3591bb96670de29a074ed9e361497d0f22b60e4ffdcd551b5d284766a
- Enrichment time
- 2026-05-15T20:52:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.