INTEL_REPORT
Snyk Blog — AppSec & supply chain · published 5/11/2026, 5:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack On May 11, 2026, the Mini Shai-Hulud worm compromised 84 npm package artifacts across 42 @tanstack/* packages (as well as @squawk/*, @mistralai/* packages, and others) by chaining a GitHub Actions "Pwn Request," cache poisoning, and OIDC token extraction from runner memory — producing the first npm supply chain attack with valid SLSA Build Level 3 attestations. Here's what happened, what was sto…
https://snyk.io/blog/tanstack-npm-packages-compromised
sha256:2be394a3b54bc6673ed9f2f65a62d18293dfe917d7660ce82574662990b24db2
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| process.env |
| Open → |
| domain | registry.npmjs.org | Open → |
| domain | api.github.com | Open → |
| domain | kubernetes.io | Open → |
| domain | getsession.org | Open → |
| domain | app.snyk.io | Open → |
| domain | app.us.snyk.io | Open → |
| domain | app.eu.snyk.io | Open → |
| domain | app.au.snyk.io | Open → |
| domain | plus.probely.app | Open → |
| domain | tasks.json | Open → |
| domain | bun.gunzipsync | Open → |
| domain | pnpm-lock.yaml | Open → |
| domain | release.yml | Open → |
| domain | trigger.dev | Open → |
| domain | bundle-size.yml | Open → |
| domain | github.event | Open → |
| domain | buffer.from | Open → |
| domain | databuf.subarray | Open → |
| domain | decipher.setauthtag | Open → |
| domain | buffer.concat | Open → |
| domain | decipher.update | Open → |
| domain | decipher.final | Open → |
| domain | filev2.getsession.org | Open → |
| domain | gh-token-monitor.sh | Open → |
| domain | gh-token-monitor.service | Open → |
| domain | com.user.gh-token-monitor.plist | Open → |
| domain | api.masscan.cloud | Open → |
| domain | git-tanstack.com | Open → |
| domain | litter.catbox.moe | Open → |
| domain | 7rrc6l.mjs | Open → |
| domain | bunfig.toml | Open → |
| domain | uv.toml | Open → |
| domain | snyk.io | Open → |
| url | https://registry.npmjs.org/-/v1/search?text=maintainer:<username> | Open → |
| url | https://github.com/zblgg/configuration | Open → |
| sha1 | 79ac49eedf774dd4b0cfa308722bc463cfe5885c | Open → |
| sha1 | d4323d4df104b026a6aa633fdb11d772146be0bf | Open → |
| sha256 | 0c0e873033875f1bc471eda37e3b9d0f9b89bd41a4bbb4f86746caa2186c40aa | Open → |
| sha256 | ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c | Open → |
| sha256 | 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96 | Open → |
| cve | CVE-2026-45321 | Open → |