Shai-Hulud-Style npm Worm Hits
Multiple npm packages across @tanstack, @mistralai, @uipath, @squawk, and safe-action namespaces were compromised in a worm-like attack affecting over 50 packages. The malicious code executes during installation, downloading the Bun runtime and running a payload that harvests GitHub credentials and cloud secrets. The attack specifically targets AWS environments by querying the IMDS and attempting privilege escalation through STS and SSM endpoints across multiple regions. Stolen credentials are automatically used to publish additional malicious package versions across different maintainer accounts, creating a self-propagating infection chain. The attack patterns mirror previous Shai-Hulud compromises, using a drop-and-execute technique and command-and-control infrastructure at git-tanstack.com, a domain designed to mimic legitimate tanstack.com traffic. Organizations should rotate GitHub credentials, audit AWS credentials, and check for suspicious activity.
AI Analysis
Technical Summary
This campaign involves a worm-like compromise of over 50 npm packages across multiple namespaces such as @tanstack, @mistralai, @uipath, @squawk, and safe-action. The malicious code activates during installation, downloading the Bun runtime to execute a payload that harvests GitHub credentials and cloud secrets. It specifically targets AWS environments by querying the Instance Metadata Service (IMDS) and attempts privilege escalation through AWS STS and SSM endpoints across multiple regions. The stolen credentials are then used automatically to publish additional malicious package versions under different maintainer accounts, enabling self-propagation. The attack employs a drop-and-execute method and uses a command-and-control domain (git-tanstack.com) designed to mimic legitimate tanstack.com traffic, consistent with previous Shai-Hulud-style compromises.
Potential Impact
The attack results in theft of GitHub credentials and cloud secrets, enabling unauthorized access to AWS environments. This can lead to privilege escalation and further compromise of cloud resources. The self-propagating nature of the attack increases the risk of widespread supply chain contamination across npm packages. The use of stolen credentials to publish malicious package versions undermines trust in affected namespaces and can lead to further downstream infections.
Mitigation Recommendations
No official patch or fix is indicated for the compromised packages. Organizations should immediately rotate all GitHub credentials and audit AWS credentials for unauthorized use. Monitoring for suspicious activity related to npm package publishing and AWS access is recommended. Due to the self-propagating nature of the attack, affected maintainers should review their package integrity and consider removing or rebuilding compromised packages. Follow vendor or repository advisories for updates and remediation guidance.
Indicators of Compromise
- domain: git-tanstack.com
- hash: 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96
- hash: b82e54923f7e440664d2d75bd31588ca
- hash: e7d582b98ca80690883175470e96f703ef6dc497
Shai-Hulud-Style npm Worm Hits
Description
Multiple npm packages across @tanstack, @mistralai, @uipath, @squawk, and safe-action namespaces were compromised in a worm-like attack affecting over 50 packages. The malicious code executes during installation, downloading the Bun runtime and running a payload that harvests GitHub credentials and cloud secrets. The attack specifically targets AWS environments by querying the IMDS and attempting privilege escalation through STS and SSM endpoints across multiple regions. Stolen credentials are automatically used to publish additional malicious package versions across different maintainer accounts, creating a self-propagating infection chain. The attack patterns mirror previous Shai-Hulud compromises, using a drop-and-execute technique and command-and-control infrastructure at git-tanstack.com, a domain designed to mimic legitimate tanstack.com traffic. Organizations should rotate GitHub credentials, audit AWS credentials, and check for suspicious activity.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign involves a worm-like compromise of over 50 npm packages across multiple namespaces such as @tanstack, @mistralai, @uipath, @squawk, and safe-action. The malicious code activates during installation, downloading the Bun runtime to execute a payload that harvests GitHub credentials and cloud secrets. It specifically targets AWS environments by querying the Instance Metadata Service (IMDS) and attempts privilege escalation through AWS STS and SSM endpoints across multiple regions. The stolen credentials are then used automatically to publish additional malicious package versions under different maintainer accounts, enabling self-propagation. The attack employs a drop-and-execute method and uses a command-and-control domain (git-tanstack.com) designed to mimic legitimate tanstack.com traffic, consistent with previous Shai-Hulud-style compromises.
Potential Impact
The attack results in theft of GitHub credentials and cloud secrets, enabling unauthorized access to AWS environments. This can lead to privilege escalation and further compromise of cloud resources. The self-propagating nature of the attack increases the risk of widespread supply chain contamination across npm packages. The use of stolen credentials to publish malicious package versions undermines trust in affected namespaces and can lead to further downstream infections.
Mitigation Recommendations
No official patch or fix is indicated for the compromised packages. Organizations should immediately rotate all GitHub credentials and audit AWS credentials for unauthorized use. Monitoring for suspicious activity related to npm package publishing and AWS access is recommended. Due to the self-propagating nature of the attack, affected maintainers should review their package integrity and consider removing or rebuilding compromised packages. Follow vendor or repository advisories for updates and remediation guidance.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.netskope.com/blog/shai-hulud-style-npm-worm-hits-tanstack"]
- Adversary
- null
- Pulse Id
- 6a69c0698ac8620efa23e8f6
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaingit-tanstack.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96 | — | |
hashb82e54923f7e440664d2d75bd31588ca | — | |
hashe7d582b98ca80690883175470e96f703ef6dc497 | — |
Threat ID: 6a69e9799c2644c7f8735ca3
Added to database: 07/29/2026, 11:52:25 UTC
Last enriched: 07/29/2026, 14:14:51 UTC
Last updated: 07/30/2026, 01:24:43 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.