Malicious node-ipc versions published to npm in suspected maintainer account compromise
2026-05-16T20:52:01Z•e74c642711cd692f7e3181192381b6f12b4e389e3c7ccbd2fb8f1e5b5cf00c67
CVE-2026-40478GitHub ActionsOIDC token theftPyPISLSAcache poisoningcredential-stealermaintainer account compromisemalicious-packagemini-shai-huludnode-ipcnpmpackage compromisesoftware supply chaintanstackthymeleafvulnerability
What happened
Multiple active software supply-chain compromises and a high-severity template-injection vulnerability were reported in May 2026. Notable incidents include malicious node-ipc versions published to npm on 2026-05-14 (suspected maintainer account compromise), the Mini Shai-Hulud worm compromising 84 artifacts across 42 @tanstack/* npm packages via a chained GitHub Actions "Pwn Request", cache poisoning and OIDC token extraction (first npm supply-chain attack with valid SLSA Build Level 3 attestations), and a malicious lightning PyPI release that includes a Bun-based credential stealer executing
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- snyk_blog
- Record identifier
- e74c642711cd692f7e3181192381b6f12b4e389e3c7ccbd2fb8f1e5b5cf00c67
- Enrichment time
- 2026-05-16T20:52:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.