Security researchers report a fresh supply-chain attack campaign dubbed “Mini Shai-Hulud,” tied to the threat actor TeamPCP. According to accounts from multiple outlets, the campaign involves publishing malicious updates to packages on npm and PyPI that are used by software developers. The affected ecosystem reportedly includes packages associated with TanStack, Mistral AI, UiPath, OpenSearch, and Guardrails AI. In npm, the malicious updates introduce additional JavaScript functionality, including an obfuscated file referred to as “router_init.js,” which is intended to profile execution before running further logic. Another report says the operation publishes a large number of compromised releases, describing more than 400 malicious versions across 170 packages. The articles characterize the behavior as part of a campaign that modifies package contents rather than exploiting end-user systems directly. Taken together, the reporting indicates attackers are targeting widely used libraries and tooling by distributing tampered package versions through public registries. The reports do not describe confirmed real-world impacts beyond the distribution of compromised artifacts, but they emphasize that the tampering occurred in publicly available package releases.