Malicious node-ipc versions published to npm in suspected maintainer account compromise

2026-05-15T20:52:04Za75445d3591bb96670de29a074ed9e361497d0f22b60e4ffdcd551b5d284766a
@tanstackBunCVE-2026-40478GitHub ActionsMini Shai-HuludOIDC token extractionPwn RequestPyPISLSA level 3Thymeleafcache poisoningcredential stealermaintainer account compromisenode-ipcnpmpackage compromisepatchingrotate secretssupply chaintemplate injection

What happened

Multiple high-impact supply-chain compromises and malicious package releases were reported in May 2026: malicious node-ipc versions were published to npm (suspected maintainer account compromise), 84 @tanstack/* npm artifacts were compromised by the “Mini Shai-Hulud” attack chain (GitHub Actions "Pwn Request", cache poisoning, and OIDC token extraction producing builds with valid SLSA Level 3 attestations), and a PyPI release of lightning contained a Bun-based credential stealer that runs on import. Separately, Thymeleaf template injection (CVE-2026-40478, CVSS 9.1) affects Thymeleaf < 3.1.4;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
a75445d3591bb96670de29a074ed9e361497d0f22b60e4ffdcd551b5d284766a
Enrichment time
2026-05-15T20:52:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.