Mini Shai-Halud hackers release over 600 compromised npm packages – developers warned to be on guard


  • More than 600 malicious npm packages were published in a coordinated supply chain attack linked to TeamPCP’s Shai-Hulud campaign
  • The attackers compromised ecosystems including TanStack, Mistral, and antv, and introduced infostealers and persistence mechanisms into developer environments
  • Developers are advised to roll back to secure versions released before May 18 and rotate any exposed credentials

Cybercriminals released more than 600 malicious packages to the npm registry in a coordinated software supply chain attack linked to the Shai-Hulud campaign.

Several security organizations, including Socket, confirmed that on May 19, 2026, in just one hour, malicious actors managed to release 639 versions of 323 unique packages on npm, targeting software developers, open source maintainers, organizations running CI/CD pipelines, and anyone else who downloaded or relied on compromised npm.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top