Malicious node-ipc versions published to npm in suspected maintainer account compromise

2026-05-16T20:52:01Ze74c642711cd692f7e3181192381b6f12b4e389e3c7ccbd2fb8f1e5b5cf00c67
CVE-2026-40478GitHub ActionsOIDC token theftPyPISLSAcache poisoningcredential-stealermaintainer account compromisemalicious-packagemini-shai-huludnode-ipcnpmpackage compromisesoftware supply chaintanstackthymeleafvulnerability

What happened

Multiple active software supply-chain compromises and a high-severity template-injection vulnerability were reported in May 2026. Notable incidents include malicious node-ipc versions published to npm on 2026-05-14 (suspected maintainer account compromise), the Mini Shai-Hulud worm compromising 84 artifacts across 42 @tanstack/* npm packages via a chained GitHub Actions "Pwn Request", cache poisoning and OIDC token extraction (first npm supply-chain attack with valid SLSA Build Level 3 attestations), and a malicious lightning PyPI release that includes a Bun-based credential stealer executing

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
e74c642711cd692f7e3181192381b6f12b4e389e3c7ccbd2fb8f1e5b5cf00c67
Enrichment time
2026-05-16T20:52:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.