Security researchers report a fresh supply-chain attack campaign dubbed “Mini Shai-Hulud,” tied to the threat actor TeamPCP. According to accounts from multiple outlets, the campaign involves publishing malicious updates to packages on npm and PyPI that are used by software developers. The affected ecosystem reportedly includes packages associated with TanStack, Mistral AI, UiPath, OpenSearch, and Guardrails AI. In npm, the malicious updates introduce additional JavaScript functionality, including an obfuscated file referred to as “router_init.js,” which is intended to profile execution before running further logic. Another report says the operation publishes a large number of compromised releases, describing more than 400 malicious versions across 170 packages. The articles characterize the behavior as part of a campaign that modifies package contents rather than exploiting end-user systems directly. Taken together, the reporting indicates attackers are targeting widely used libraries and tooling by distributing tampered package versions through public registries. The reports do not describe confirmed real-world impacts beyond the distribution of compromised artifacts, but they emphasize that the tampering occurred in publicly available package releases.
Mini Shai-Hulud campaign targets multiple npm and PyPI packages, including TanStack and Mistral AI
Security researchers report a fresh supply-chain attack campaign dubbed “Mini Shai-Hulud,” tied to the threat actor TeamPCP. According to accounts from multiple outlets, the campaign involves publishi...
- The campaign is described as “Mini Shai-Hulud” and is linked to a threat actor called TeamPCP.
- Malicious versions are reported to be published on npm and PyPI, affecting multiple packages.
- Reported targets include packages associated with TanStack, Mistral AI, UiPath, OpenSearch, and Guardrails AI.
- On npm, compromised package versions include an obfuscated JavaScript file (“router_init.js”) intended to profile execution.
- One report says the campaign involves more than 400 malicious versions across 170 packages.
Over 400 malicious versions of 170 packages were published as part of the new Mini Shai-Hulud campaign. The post TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack appeared first on SecurityWeek.
3 months agoTeamPCP, the threat actor behind the recent supply chain attack spree, has been linked to the compromise of the npm and PyPI packages from TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI as part of a fresh Mini Shai-Hulud campaign. The affected npm packages have been modified to include an obfuscated JavaScript file ("router_init.js") that's designed to profile the execution
3 months agoOpenAI ends partnership with Cursor after SpaceX acquisition, citing contract concerns
OpenAI says it will stop supplying AI models to Cursor after SpaceX completes its acquisition of Cursor’s parent, Anysph...
Nigerian Army alerts about attempted unauthorized access to official X account
The Nigerian Army says it detects and is responding to an attempted unauthorized access to its official X account. The s...
Sony Music and Warner sue Anthropic over alleged copyright infringement
Sony Music and Warner Music Publishing sue AI company Anthropic, alleging large-scale copyright infringement. The publis...