Mini Shai-Hulud v3 — TanStack/UiPath/Mistral AI npm & PyPI Supply Chain Compromise (TeamPCP) — Threadlinqs Intelligence
As of 2026-05-30, Mini Shai-Hulud v3 — TanStack/UiPath/Mistral AI npm & PyPI Supply Chain Compromise (TeamPCP) is a critical-severity supply chain threat attributed to TeamPCP, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0499 · Severity: CRITICAL · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: TeamPCP · FINANCIAL
On 11 May 2026, the threat actor TeamPCP executed a coordinated supply-chain attack against npm and PyPI ecosystems, compromising packages including @tanstack/react-router (~12M weekly downloads),
TeamPCP, attributed with high confidence by Wiz Research, executed its third documented large-scale supply-chain attack (Mini Shai-Hulud v3) on 11 May 2026, targeting npm and PyPI ecosystems. This follows the operator's prior compromises of SAP, Checkmarx, Bitwarden, Lightning, Intercom, and Trivy packages.
The TanStack compromise exploited a three-stage GitHub Actions attack chain. First, the attacker forked TanStack/router, renaming the fork to zblgg/configuration for evasion, and submitted a pull request that triggered a pull_request_target workflow — a dangerous GitHub Actions pattern that executes with write repository permissions even for external PRs. The workflow poisoned the pnpm package store cache with malicious content. When legitimate PRs were merged and release workflows ran, they restored the poisoned cache, enabling extraction of OIDC tokens directly from GitHub Actions runner process memory (/proc/<pid>/mem). These stolen tokens were used to publish malicious package versions to npm without any credential compromise of maintainer accounts.
The UiPath namespace compromise used a preinstall hook (node setup.mjs) that downloaded the Bun JavaScript runtime (v1.3.13) and executed an obfuscated payload — identical delivery mechanism to the prior SAP compromise, re-obfuscated with a different campaign key but pointing to the same C2 infrastructure.
The Python ecosystem variant (guardrails-ai@0.10.1 and mistralai@2.4.6) contained a minimal 13-line downloader fetching and executing transformers.pyz from git-tanstack.com/tmp/. This unobfuscated modular credential stealer is Linux-only and exits gracefully if the system locale is Russian or if fewer than 4 CPU cores are detected — an anti-analysis and geopolitical evasion measure. Notably, this version includes first-documented password vault targeting (1Password, Bitwarden vaults).
All payloads function as self-propagating credential-stealing worms targeting: GitHub Actions OIDC tokens, GitLab and CircleCI tokens, AWS IMDSv2 credentials, GCP and Azure credentials, Kubernetes service account tokens, HashiCorp Vault tokens, and npm/package registry tokens. A persistent monitoring daemon (gh-token-monitor) is installed as a macOS LaunchAgent (~/Library/LaunchAgents/com.user.gh-token-monitor.plist) or Linux systemd user service (~/.config/systemd/user/gh-token-monitor.service). This daemon polls the GitHub API every 60 seconds and, critically, upon detecting token revocation (HTTP 40x response), executes rm -rf ~/ to destroy the victim home directory — a destructive wiper triggered by incident response actions. The daemon self-terminates after 24 hours.
The C2 infrastructure represents a significant evolution: a triple-layer architecture comprising (1) typosquat domain git-tanstack.com for payload hosting, (2) decentralized encrypted exfiltration via the Session messenger network (*.getsession.org) to recipient ID 05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026, and (3) GitHub API dead drops where stolen tokens are stored in Dune-themed repositories (description: 'Shai-Hulud: Here We Go Again'). A commit with message 'IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner' served as an explicit threat indicator. Self-propagation uses stolen npm tokens and GitHub OIDC to publish poisoned versions of additional packages the victim can write to, exponentially expanding the attack blast radius.
In total, 131+ npm packages across 15+ namespaces were compromised including @tanstack (12M weekly downloads on react-router alone), @uipath (60+ packages), @mistralai, @beproduct, @cap-js, @dirigible-ai, @draftauth, @draftlab, @mesadev, @ml-toolkit-ts, @opensearch-project, @squawk, @supersurkhet, @tallyui, @taskflow-corp, and @tolka. Runtime artifacts (router_runtime.js, tanstack_runner.js) persist in IDE directories (.claude/, .vscode/) even after npm uninstall, requiring manual remediation. BeaconBeagle lookup for C2 IP 83.142.209.194 returned no prior beacon hit
Weaknesses (CWE)
CWE-494, CWE-829, CWE-506, CWE-522
Target sectors: technology, software-development, ai-ml, enterprise-software, devops, cloud, financial
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, CRITICAL, threat intelligence, cybersecurity, T1583.001, T1586.003, T1608.001, T1195.001, T1199, T1059.007, T1059.006, T1072, T1543.001, T1543.002