MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Mini Shai-Hulud compromises TanStack packages and propagates downstream

On 11 May 2026 attackers compromised TanStack's Router/Start publishing workflow and released 84 malicious versions across 42 npm packages. The compromise propagated downstream: Mistral confirmed malicious SDK releases and an affected developer device, while OpenAI confirmed two employee devices were impacted, limited credential material was exfiltrated and code-deployment workflows were temporarily restricted.

83

Estimated severity

83 / 100

94

Source reliability

94 / 100

Approximate Date

11/05/2026

Targeted Company

TANSTACK

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

MISTRAL AI (Software vendor)OPENAI (Software vendor)

Geographic Impact

Country Targeted Company

Country visual unavailable

No information

Other Affected Countries

No other affected countries reported

Target country

No information

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impactDownstream customer disruption

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseMalwareData exfiltrationExploitation of misconfiguration

Attributed threat actors

TEAMPCP

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.