ended5월 13일· 1 sources
Inside Mini Shai-Hulud: The Self-Propagating Supply-Chain Worm
공급망 공격의 새로운 위협: 자가증식 웜 Mini Shai-Hulud
Why it matters
The May 2026 TanStack npm compromise affecting 42 packages was part of Mini Shai-Hulud, a self-propagating supply-chain worm that uses developer machines and CI/CD pipelines as stepping stones to compromise subsequent packages and maintainers. This represents a critical evolution in supply-chain attacks—rather than isolated breaches, attackers exploit the ecosystem to spread automatically. Understanding how GitHub Actions cache poisoning and OIDC token extraction enabled this worm-like propagation is essential for developers to secure their release pipelines.
1
Sources
+0
24h
—
Growth
6d
Active
TanStacksupply-chain wormcache poisoningGitHub Actionsnpmcredential stealer