Mini Shai-Hulud supply-chain campaign targeting npm and PyPI
Campaign
Summary
Hide ▲
Show ▼
The Mini Shai-Hulud supply-chain campaign linked to TeamPCP expanded into downstream victim reporting, including Grafana Labs. Grafana said its GitHub environment was accessed, its codebase was downloaded, and additional internal operational information was taken after malicious TanStack npm packages were consumed by its CI/CD environment. The company said it first saw the activity on May 11 and later discovered the unauthorized download on May 17; it also said there is no indication customer production systems or operations were compromised.
Related Happenings
AsyncAPI repositories and npm publishing workflow hit by network compromise
Incident
H score27
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
AsyncAPI repositories and npm publishing workflow hit by network compromise
IncidentAbout this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
OpenMandriva Linux project hit by cyberattack
Incident
H score32
First: 10.07.2026 01:14
Last: 10.07.2026 01:14
Sources 1
About this happening:
The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...
OpenMandriva Linux project hit by cyberattack
IncidentAbout this happening: The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...
North Korean Contagious Interview PolinRider supply-chain campaign
Campaign
H score51
First: 04.07.2026 14:17
Last: 04.07.2026 14:17
Sources 1
About this happening:
The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
North Korean Contagious Interview PolinRider supply-chain campaign
CampaignAbout this happening: The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
Codfish/semantic-release-action hit by network compromise
Incident
H score21
First: 26.06.2026 14:05
Last: 26.06.2026 14:05
Sources 1
About this happening:
The codfish/semantic-release-action GitHub Action was hit by a malicious commit force-push and tag redirection that caused trusted workflows to run attacker code. The...
Codfish/semantic-release-action hit by network compromise
IncidentAbout this happening: The codfish/semantic-release-action GitHub Action was hit by a malicious commit force-push and tag redirection that caused trusted workflows to run attacker code. The...
Sapphire Sleet Mastra npm supply-chain campaign
Campaign
H score42
First: 20.06.2026 17:09
Last: 20.06.2026 17:09
Sources 1
About this happening:
The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff after Microsoft said the operation compromised the npm maintainer account "ehindero...
Sapphire Sleet Mastra npm supply-chain campaign
CampaignAbout this happening: The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff after Microsoft said the operation compromised the npm maintainer account "ehindero...
Timeline
-
21.05.2026 11:00 1 articles · 1mo ago
Grafana Labs reports GitHub codebase breach tied to Mini Shai-Hulud
Victim Impact UpdateGrafana Labs said its GitHub environment was accessed and its codebase downloaded, with additional internal operational information taken from GitHub repositories, after compromise linked to the Mini Shai-Hulud campaign and TanStack npm packages. Grafana said it first spotted malicious activity on May 11, discovered the unauthorized download on May 17, and after contact from the ransom gang rotated automation tokens, enabled enhanced monitoring, audited commits since the May 11 incident, and hardened its GitHub security posture, while saying there is no indication customer production systems or operations were compromised.
Show sources
- Grafana Labs Says Code Breach Stemmed from TanStack Attack — www.infosecurity-magazine.com — 21.05.2026 11:00
-
12.05.2026 17:45 1 articles · 2mo ago
Mini Shai-Hulud supply-chain campaign targeting npm and PyPI
Initial DisclosureThe operation began in April 2026 with targeting of SAP-related packages before escalating into a broader multi-ecosystem supply-chain effort. The early phase established the release-pipeline abuse pattern later used in the May 11, 2026 TanStack wave.
Show sources
- Mini Shai-Hulud Hits TanStack npm Packages — www.infosecurity-magazine.com — 12.05.2026 17:45
-
12.05.2026 17:45 1 articles · 2mo ago
Mini Shai-Hulud compromises 42 TanStack npm packages
Exploitation ObservedOn May 11, 2026, TeamPCP-linked Mini Shai-Hulud published 84 malicious versions across 42 @tanstack/* npm packages by abusing legitimate release pipelines; the affected TanStack packages included @tanstack/react-router, and the payload added router_init.js and an optionalDependencies path to @tanstack/setup to steal CI credentials, including GitHub Actions secrets.
Show sources
- Mini Shai-Hulud Hits TanStack npm Packages — www.infosecurity-magazine.com — 12.05.2026 17:45