TanStack hit by network compromise
Incident
Summary
Hide ▲
Show ▼
TanStack was hit by a package compromise on May 11, 2026, when attackers published 84 malicious versions across 42 @tanstack/* packages and abused the release path so downstream installs could run attacker code. The broader Mini Shai-Hulud campaign used those packages to target CI/CD environments and steal tokens, and later reporting linked Grafana Labs’ GitHub breach and code theft to the same activity. Grafana said the attacker accessed its GitHub environment, downloaded its codebase, and took some internal operational information, while stating there is no indication customer production systems or the Grafana Cloud platform were compromised.
Related Happenings
AsyncAPI repositories and npm publishing workflow hit by network compromise
Incident
H score27
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
AsyncAPI repositories and npm publishing workflow hit by network compromise
IncidentAbout this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
OpenMandriva Linux project hit by cyberattack
Incident
H score32
First: 10.07.2026 01:14
Last: 10.07.2026 01:14
Sources 1
About this happening:
The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...
OpenMandriva Linux project hit by cyberattack
IncidentAbout this happening: The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...
Injective Labs SDK project GitHub repository hit by network compromise
Incident
H score21
First: 09.07.2026 23:10
Last: 09.07.2026 23:10
Sources 1
About this happening:
The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...
Injective Labs SDK project GitHub repository hit by network compromise
IncidentAbout this happening: The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...
Malicious npm and PyPI payment SDK typosquat packages
Malware Activity
H score40
First: 09.07.2026 18:09
Last: 09.07.2026 18:09
Sources 1
About this happening:
The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
Malicious npm and PyPI payment SDK typosquat packages
Malware ActivityAbout this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
North Korean Contagious Interview PolinRider supply-chain campaign
Campaign
H score51
First: 04.07.2026 14:17
Last: 04.07.2026 14:17
Sources 1
About this happening:
The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
North Korean Contagious Interview PolinRider supply-chain campaign
CampaignAbout this happening: The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
Timeline
-
21.05.2026 11:00 1 articles · 1mo ago
Grafana Labs reports GitHub codebase theft after TanStack-linked compromise
Victim Impact UpdateOn May 17, 2026, Grafana Labs said an unauthorized attacker had downloaded its codebase after accessing the firm's GitHub environment, and the company later said additional internal operational information and business contact names and email addresses were taken from its GitHub repositories; Grafana Labs said there was no indication that customer production systems or the Grafana Cloud platform were compromised.
Show sources
- Grafana Labs Says Code Breach Stemmed from TanStack Attack — www.infosecurity-magazine.com — 21.05.2026 11:00
-
12.05.2026 17:45 2 articles · 2mo ago
TanStack hit by network compromise
Initial DisclosureThe initial compromise appeared on May 11, 2026, when malicious versions were published across 42 @tanstack/* packages within minutes. Early evidence showed the release pipeline was abused to seed installer-executed payloads into downstream environments.
Show sources
- Mini Shai-Hulud Hits TanStack npm Packages — www.infosecurity-magazine.com — 12.05.2026 17:45
- Mini Shai-Hulud Hits TanStack npm Packages — www.infosecurity-magazine.com — 12.05.2026 17:45