DEV Community

Achin Bansal
Achin Bansal

Posted on • Originally published at gridthegrey.com

Supply Chain Worm Compromises Mistral AI, Guardrails AI and TanStack Packages

Forensic Summary

The TeamPCP threat actor has executed a broad supply chain campaign dubbed Mini Shai-Hulud, injecting credential-stealing malware into npm and PyPI packages from major AI and developer tooling ecosystems including Mistral AI, Guardrails AI, and TanStack. The malware profiles execution environments, exfiltrates cloud, CI, and AI tool credentials, and establishes persistence inside Claude Code and VS Code IDEs. The TanStack compromise alone affected 42 packages and 84 versions, exploiting a chained GitHub Actions attack to inject malicious payloads without stealing npm tokens directly.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/supply-chain-worm-compromises-mistral-ai-guardrails-ai-and-tanstack-packages/

Top comments (0)