How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack

calendar_today May 11, 2026 person domain snyk

On May 11, 2026, the Mini Shai-Hulud worm compromised 84 npm package artifacts across 42 @tanstack/* packages (as well as @squawk/, @mistralai/ packages, and others) by chaining a GitHub Actions “Pwn Request,” cache poisoning, and OIDC token extraction from runner memory — producing the first npm supply chain attack with valid SLSA Build Level 3 attestations. Here’s what happened, what was stolen, and what you need to do right now.

open_in_new Read original post