Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

TanStack npm Packages Hit by Mini Shai-Hulud

Blog post from Snyk

Post Details
Company
Date Published
Author
Stephen Thoemmes
Word Count
3,729
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

On May 11, 2026, a supply chain attack affected the TanStack npm packages, with 84 malicious package artifacts published across 42 packages in the @tanstack namespace. This incident, attributed to the threat group TeamPCP, marked the first time a malicious npm package carried valid SLSA provenance, a cryptographic certificate meant to verify the package's trusted source. The attack was executed through a hijacking of TanStack's release pipeline, allowing attacker-controlled code to publish malicious packages via a trusted identity. The rapid spread affected numerous organizations, including Mistral AI and UiPath, with @tanstack/react-router alone receiving over 12.7 million weekly downloads. This was part of a broader series of npm supply chain attacks using the Shai-Hulud worm toolchain. The worm exploited vulnerabilities in GitHub Actions, such as OIDC token extraction and cache poisoning, to publish malicious versions with valid attestations. The attack's persistence mechanisms included hooks in developer tooling directories and a dead-man's switch system-level script, highlighting the sophisticated nature of the campaign.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 16 2,324 403 114 +18%
Kubernetes 5 2,019 384 116 -16%
AI Agents 2 5,657 1,451 270 -3%
AI Coding Assistant 2 1,996 587 182 +13%
MCP 2 7,755 814 203 -3%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.