Mistral AI, TanStack npm packages compromised in 'mini Shai Hulud' supply-chain malware campaign
Compromised Mistral AI and TanStack packages in npm have exposed GitHub, cloud, and CI/CD credentials in a supply-chain attack dubbed 'mini Shai Hulud'. The malware campaign is spreading across npm and AI developer ecosystems, affecting open-source developers relying on these libraries.
Development teams should audit dependencies immediately and rotate credentials for any CI/CD systems connected to affected build pipelines. The attack underscores supply-chain risks in AI tooling and the importance of vendoring or lockfile verification practices.