> Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
[AUTHOR: Bill Toulas]
[DATE: 12/05/2026 11:29]
[LANGUAGE: EN]
Hundreds of packages across npm and PyPI have been compromised in a new Shai-Hulud supply-chain campaign delivering credential-stealing malware targeting developers. [...]