The NPM Worm Is Back And It's So Much Worse (TanStack Hacked)
Shai Hulud is back for round four, and this time it hit TanStack — publishing 84 malicious versions across 42 packages in minutes. This attack includes a deadman switch that wipes your PC if you rotate stolen credentials, steals everything from AWS keys to Claude Code session history, and abused GitHub Actions cache poisoning + OIDC trusted publishing to look completely legitimate. This is the most sophisticated NPM supply chain attack I've seen. Let's break it down. 🔗 Relevant Links https://www.stepsecurity.io/blog/mini... https://socket.dev/blog/tanstack-npm-... https://snyk.io/blog/tanstack-npm-pac... https://www.wiz.io/blog/mini-shai-hul... ❤️ More about us Radically better observability stack: https://betterstack.com/ Written tutorials: https://betterstack.com/community/ Example projects: https://github.com/BetterStackHQ 📱 Socials Twitter: / betterstackhq Instagram: / betterstackhq TikTok: / betterstack LinkedIn: / betterstack 📌 Chapters: 0:00 0:37 Overview 0:54 What it does 2:37 What it steals 4:09 Self-destruct 5:07 Self-propagation (wormin) 6:42 How TanStack got infected 8:44 Summary

I Don't Think I Can Go Back To Windows...

TanStack & MANY more packages affected - a deep dive & analysis

Why does this keep happening?

This Battery Doesn't Need Lithium and It Just Hit Mass Production

Mini Shai-Hulud: The npm Worm That Signs Its Own Malware (May 2026)

A single PR just hijacked the NPM registry...

I Hacked This Temu Router. What I Found Should Be Illegal.

the npm malware is a hacking masterpiece

I am done with Golang

A Hacker Found The BitLocker Backdoor

Protecting against supply chain attacks - full guide

Passkeys Explained: Are They Actually Better Than Passwords?

They Hit TanStack. 518 Million Downloads. And the Security Cert Was Real.

npm installs can hack your laptop (Here's how to stop it)

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains

The largest supply-chain attack ever…

this may be the worst one

Shai-Hulud is Back: TanStack & Mistral AI Breach by TeamPCP Mini Worm

I tried finding Hidden Gems on AliExpress AGAIN! (Part 19)

