Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Shai-Hulud compromises the @tanstack ecosystem: 160+ packages compromised

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Peyton Kennedy
Word Count
2,916
Company Posts That Month
25
Language
English
Hacker News Points
-
Post removed?
No
Summary

In May 2026, attackers compromised over 160 package versions in the npm ecosystem, embedding credential-stealing malware within popular libraries, particularly targeting GitHub Actions secrets and other sensitive credentials. The attack, part of the Shai-Hulud malware family, marked its fifth occurrence within eight months and the second in two weeks. It exploited a novel technique involving an orphaned commit pushed to a fork of the TanStack repository, enabling the attacker to acquire a legitimate short-lived npm publish token despite TanStack's adherence to security measures like 2FA and OIDC trusted publishing. The campaign's payload, obscured by sophisticated obfuscation techniques, allowed for widespread deployment and replication, leveraging GitHub's shared object storage and bypassing branch protection rules. This attack is a significant escalation in the technical sophistication of the Shai-Hulud campaigns, highlighting vulnerabilities in dependency management and the importance of narrowing OIDC trust scopes to prevent unauthorized workflows.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 11 2,152 360 101 +18%
Kubernetes 4 1,965 371 106 -15%
Observability 3 3,421 707 180 -24%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.