Find notable cyber news and cases, enriched with sources, timelines, and signals.

Mini Shai-Hulud supply-chain campaign targeting npm and PyPI

Campaign
First reported
Last updated
Happening score
H score 45
1 unique sources, 2 articles

Summary

Hide ▲

The Mini Shai-Hulud supply-chain campaign linked to TeamPCP expanded into downstream victim reporting, including Grafana Labs. Grafana said its GitHub environment was accessed, its codebase was downloaded, and additional internal operational information was taken after malicious TanStack npm packages were consumed by its CI/CD environment. The company said it first saw the activity on May 11 and later discovered the unauthorized download on May 17; it also said there is no indication customer production systems or operations were compromised.

Related Happenings

AsyncAPI repositories and npm publishing workflow hit by network compromise

Incident
H score27 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...

OpenMandriva Linux project hit by cyberattack

Incident
H score32 First: 10.07.2026 01:14 Last: 10.07.2026 01:14 Sources 1

About this happening: The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...

North Korean Contagious Interview PolinRider supply-chain campaign

Campaign
H score51 First: 04.07.2026 14:17 Last: 04.07.2026 14:17 Sources 1

About this happening: The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....

Codfish/semantic-release-action hit by network compromise

Incident
H score21 First: 26.06.2026 14:05 Last: 26.06.2026 14:05 Sources 1

About this happening: The codfish/semantic-release-action GitHub Action was hit by a malicious commit force-push and tag redirection that caused trusted workflows to run attacker code. The...

Sapphire Sleet Mastra npm supply-chain campaign

Campaign
H score42 First: 20.06.2026 17:09 Last: 20.06.2026 17:09 Sources 1

About this happening: The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff after Microsoft said the operation compromised the npm maintainer account "ehindero...

Timeline

  1. 21.05.2026 11:00 1 articles · 1mo ago

    Grafana Labs reports GitHub codebase breach tied to Mini Shai-Hulud

    Victim Impact Update

    Grafana Labs said its GitHub environment was accessed and its codebase downloaded, with additional internal operational information taken from GitHub repositories, after compromise linked to the Mini Shai-Hulud campaign and TanStack npm packages. Grafana said it first spotted malicious activity on May 11, discovered the unauthorized download on May 17, and after contact from the ransom gang rotated automation tokens, enabled enhanced monitoring, audited commits since the May 11 incident, and hardened its GitHub security posture, while saying there is no indication customer production systems or operations were compromised.

    Show sources
  2. 12.05.2026 17:45 1 articles · 2mo ago

    Mini Shai-Hulud supply-chain campaign targeting npm and PyPI

    Initial Disclosure

    The operation began in April 2026 with targeting of SAP-related packages before escalating into a broader multi-ecosystem supply-chain effort. The early phase established the release-pipeline abuse pattern later used in the May 11, 2026 TanStack wave.

    Show sources
  3. 12.05.2026 17:45 1 articles · 2mo ago

    Mini Shai-Hulud compromises 42 TanStack npm packages

    Exploitation Observed

    On May 11, 2026, TeamPCP-linked Mini Shai-Hulud published 84 malicious versions across 42 @tanstack/* npm packages by abusing legitimate release pipelines; the affected TanStack packages included @tanstack/react-router, and the payload added router_init.js and an optionalDependencies path to @tanstack/setup to steal CI credentials, including GitHub Actions secrets.

    Show sources