HomeSecurityMistral AI SDK and TanStack Router victims of supply chain attack

Mistral AI SDK and TanStack Router victims of supply chain attack

Threat group TeamPCP has carried out another major attack on the software supply chain, successfully compromising 170 Node Package Manager (npm) and PyPI packages in a matter of hours this week . The attack affected the entire ecosystem of TanStack Router (@tanstack) , a routing library that is extremely popular among React web application developers .

See also: Mini Shai-Hulud Worm: Infects TanStack, Mistral AI and other Packages

TanStack Router
Mistral AI SDK and TanStack Router victims of supply chain attack

Multiple other packages were also affected, including @squawk (87 packages), @uipath (66 packages), @tallyui (30 packages), @beproduct (18 packages), as well as the Mistral AI SDK suite on both npm and PyPI, and the Guardrails AI PyPI package. The attacks, observed by multiple vendors using automated security tools, occurred on May 11 and spread rapidly through package ecosystems thanks to the worm capabilities of the Mini Shai-Hulud automated malware platform, the analysis showed.

The exact number of package versions affected by the attack varies depending on the source. According to Aikido Security, it was 373 across 169 package namespaces, while SafeDep reported the number was 404 package versions across 170 npm packages, with two affecting PyPI. A striking feature of the attacks is the ease with which the TeamPCP threat group, blamed for the attack, was able to take over legitimate project pipelines by exploiting a combination of maintainer misconfigurations and GitHub Actions.

Instead of directly stealing maintainer credentials, the attackers exploited a dangerous trigger, pull_request_target. This allows third-party workflows to be executed automatically – a way to avoid maintainer approval fatigue – but it means that maintainers’ short-lived OIDC tokens become vulnerable to scraping. Armed with these tokens, the attackers were able to compromise the packages by injecting the Mini Shai-Hulud malware, which spread to other projects.

The purpose is to steal developer credentials such as GitHub and npm tokens, cloud credentials, API keys, Kubernetes service accounts, and SSH keys.

See also: ZiChatBot Malware: Malicious PyPI Packages Target Windows and Linux

Mistral AI SDK and TanStack Router victims of supply chain attack
Mistral AI SDK and TanStack Router victims of supply chain attack

The malware also installs a destructive ' kill switch ' that attempts to delete the user's entire home directory if a developer revokes a stolen GitHub token. Attacks by TeamPCP targeting software supply chains have become a recurring theme in recent months. This includes a similar breach in April of the command-line version of the Bitwarden password manager .

A month earlier, it was Aqua Security ’s open-source vulnerability scanner Trivy , which was later revealed to have caused a data breach on the EU’s Europa.eu website . According to Abhisek Datta , founder of SafeDep, one of the first vendors to detect the breach, TeamPCP appears to have designed the campaign to target developers in the US. “ They know that high-profile attacks will be quickly detected by the industry. By targeting specific working hours in the US, they likely want to maximize their performance during a short window of opportunity ,” he said via email.

“The way software usage and the trust network have evolved, mostly leaning towards implicit trust, is probably the root of the problem that these attacks exploit. Unfortunately, it’s hard to fix, especially today where developers and software companies expect speed above all else.” Developers could add more security around packages, but that would create additional friction, Datta said.

“Honestly, I would say this is something that people are still trying to figure out.” SafeDep has published a full list of affected packages, with indicators of compromise. If any of the compromised packages are in use, the recommended actions are to check the lock file for known compromised versions, pin dependencies to known good versions, and check for evidence of malicious files.

See also: Contagious Interview – North Korea: 1,700 malicious npm, PyPI, Go, Rust packages

Mistral AI SDK and TanStack Router victims of supply chain attack
Mistral AI SDK and TanStack Router victims of supply chain attack

If you suspect an infected version, the credentials used during import should be rotated.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS