Large npm Supply-Chain Attack Hits TanStack, Mistral AI, UiPath, and Others
Socket identified the Mini Shai-Hulud supply-chain attack, where attackers used three GitHub Actions flaws to publish nearly 373 malicious versions across more than 160 npm package names, affecting projects including TanStack, Mistral AI, and UiPath and stealing AWS, GCP, Kubernetes, GitHub tokens, and SSH private keys during installation.
Why it matters: HKR-H/K/R all pass: named projects create the hook, Socket provides concrete counts and mechanisms, and credential theft matters to AI engineering teams. It is a strong security incident, not a core model or product release, so it stays in the 78–84 band.