# Socket Weekly: Mini Shai-Hulud Hits TanStack, TeamPCP Gamifies Supply…

Canonical: https://brew.new/browse/templates/email/pt1_k97j6612er60qwtzkpdxkz457d8e496h

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: Mini Shai-Hulud Hits TanStack, TeamPCP Gamifies Supply…](https://cdn.brew.new/email-preview-0a6a9cf3455f212a-tracking_r57ppvd0km9tqa2m657vxchwhn8dvh8h-1789015377711.png)

## Email content

socket-weekly-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack

Attackers published 84 malicious versions across 42 @tanstack/* packages, including @tanstack/react-router (12 million weekly downloads), in the latest wave of the Mini Shai-Hulud campaign. Socket detected the compromised packages within six minutes of publication. The campaign has been working through high-trust namespaces across npm, PyPI, and Packagist for weeks, with earlier waves hitting UiPath, Mistral AI, OpenSearch, and Intercom's PHP and JavaScript SDKs.

MORE NEWS

TeamPCP and BreachForums Launch $1,000 Contest for Supply Chain Attacks

TeamPCP and BreachForums are running a $1,000 Monero contest for the biggest open source supply chain compromise, scored by weekly and monthly download counts, with the usual cybercrime forum currency of reputation and bragging rights on the side. Never ones to miss a punchline, TeamPCP also released Shai-Hulud as open source attack tooling so contestants don't have to write the malware themselves.

Popular node-ipc npm Package Infected with Credential Stealer

Three malicious versions of node-ipc shipped a credential stealer targeting 90+ categories of developer and cloud secrets, exfiltrated through DNS TXT queries to blend into normal traffic. The attacker never touched npm or the active maintainers; they re-registered an expired email domain tied to a dormant maintainer account and used a routine password reset to gain publish rights, a reminder that abandoned accounts on widely used packages are their own category of supply chain risk.

MORE WORTH READING

Mythos finds a curl vulnerability

Packagist Urges Immediate Composer Update After GitHub Actions Token Leak

Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt

OpenAI: Our response to the TanStack npm supply chain attack

GitHub App installation tokens: Per-request override header

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97j6612er60qwtzkpdxkz457d8e496h)

[Browse email designs](https://brew.new/browse/templates)
