May 14, 2026security
Mini Shai-Hulud: How the TanStack npm Attack Spread to PyPI and Why Your CI/CD Is the New Attack Surface
On May 11, 2026, a threat actor group known as TeamPCP executed one of the most technically sophisticated open source supply chain attacks ever documented. In under 48 hours, their worm, dubbed "Mini Shai-Hulud," spread across 172 packages totaling over 403 malicious published versions across both npm and PyPI. The targets included the entire TanStack router ecosystem, Mistral AI's Python and JavaScript SDKs, UiPath's automation packages, OpenSearch, and Guardrails AI.