Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
From BleepingComputer to All on Tue May 12 07:45:58 2026
Hundreds of packages across npm and PyPI have been compromised in a new Shai-Hulud supply-chain campaign delivering credential-stealing malware targeting developers. [...]