# First npm Worm With Valid SLSA Attestations Spreads Across TanStack, Mistral AI, OpenSearch, and More


## The Threat


A sophisticated supply chain worm designated CVE-2026-45321 has compromised multiple critical open source packages across npm and PyPI, marking a significant escalation in software supply chain attacks. Attributed to threat actor TeamPCP, the "Mini Shai-Hulud" campaign has infected 42 TanStack packages spanning 84 distinct versions, along with packages from UiPath, Mistral AI, OpenSearch, Guardrails AI, and others.


The compromised packages contain obfuscated JavaScript code (filename: "router_init.js") that profiles the execution environment and deploys a comprehensive credential stealer. The malware targets a broad attack surface: cloud provider credentials, cryptocurrency wallets, AI platform tokens, messaging applications, and critical CI/CD systems including GitHub Actions, Aikido Security, Endor Labs, SafeDep, Socket, and StepSecurity. The stolen credentials are exfiltrated via the decentralized Session Protocol infrastructure—a deliberate choice to evade enterprise detection, since organizations are unlikely to block traffic to a privacy-focused messaging service.


What distinguishes this campaign from previous supply chain attacks is its self-replicating capability and persistence mechanisms. The worm establishes hooks in Claude Code and Microsoft Visual Studio Code to survive system reboots, installs a gh-token-monitor service to continuously re-exfiltrate GitHub tokens, and injects malicious GitHub Actions workflows that serialize repository secrets and upload them to attacker infrastructure.


## Severity and Impact


| Attribute | Details |

|-----------|---------|

| CVE Identifier | CVE-2026-45321 |

| CVSS Score | 9.6 (Critical) |

| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |

| CWE | CWE-506 (Embedded Malicious Code) |

| Attack Complexity | Low |

| Privileges Required | None |

| User Interaction | None |

| Scope | Unchanged |

| Affected Versions | TanStack: 42 packages, 84 versions; Mistral AI, OpenSearch, Guardrails AI, and others |


The worm's ability to generate valid SLSA Build Level 3 provenance attestations is particularly alarming. SLSA provenance was designed to establish a chain of custody for software artifacts, allowing developers and organizations to verify that packages come from legitimate build environments. This is the first documented case of a supply chain worm producing cryptographically valid, trusted attestations—effectively poisoning one of the industry's primary defenses against malicious software.


According to TanStack's investigation, the compromise exploited a chained attack involving GitHub Actions' pull_request_target trigger, GitHub Actions cache poisoning, and runtime extraction of OIDC tokens from the Actions runner environment. No npm tokens were directly stolen, and the npm publish workflow itself was not compromised; instead, attackers staged the malicious payload in a forked repository, injected it into published tarballs, and hijacked the legitimate workflow to publish compromised versions.


## Affected Products


npm Packages:

  • TanStack ecosystem: 42 packages across 84 versions (including @tanstack/router and related projects)
  • @opensearch-project/opensearch (versions 3.5.3, 3.6.2, 3.7.0, 3.8.0)
  • @squawk/mcp (version 0.9.5)
  • @squawk/weather (version 0.5.10)
  • @squawk/flightplan (version 0.5.6)
  • @tallyui/connector-medusa (versions 1.0.1, 1.0.2, 1.0.3)
  • @tallyui/connector-vendure (versions 1.0.1, 1.0.2, 1.0.3)
  • UiPath packages
  • DraftLab packages

  • PyPI Packages:

  • mistralai (version 2.4.6)
  • guardrails-ai (version 0.10.1)

  • ## Mitigations


    Immediate Actions:


    1. Update all affected packages to patched versions immediately. Check your dependency trees and lock files for any of the listed package versions.


    2. Rotate all GitHub tokens with elevated permissions, particularly those configured with bypass_2fa set to true. These tokens are prime targets for the worm's self-replication mechanism.


    3. Audit GitHub Actions workflows in all repositories where developers use the affected packages. Look for suspicious workflows created or modified during the compromise window, and review all recent repository secret usage.


    4. Inspect IDE configurations for persistence hooks. Check your local VS Code and Claude Code settings for malicious extensions or hooks, particularly in settings.json and extension manifests.


    5. Review CI/CD logs and environment variables for evidence of token exfiltration. Search logs for connections to filev2.getsession[.]org, api.masscan[.]cloud, or commits from the attacker email claude@users.noreply.github.com.


    6. Enable token monitoring and rotation policies in your GitHub organization. Implement short-lived token expiration, disable tokens with bypass_2fa enabled, and use fine-grained personal access tokens with minimal scope.


    7. Review supply chain security tooling. If you use Aikido Security, Endor Labs, SafeDep, or Socket, audit their configuration and logs for unauthorized access or token exfiltration.


    ## References


  • [CVE-2026-45321 Details](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45321)
  • [TanStack Supply Chain Incident Report](https://tanstack.com/security)
  • [StepSecurity Analysis: First npm Worm with Valid SLSA Attestations](https://stepsecurity.io)
  • [Microsoft Threat Intelligence on mistralai Compromise](https://microsoft.com/security)

  • ---


    ## HackWire Analysis


    The Mini Shai-Hulud worm represents a watershed moment in software supply chain security. For years, industry experts have warned that SLSA provenance and similar attestation mechanisms could become double-edged swords if attackers gained the ability to generate valid credentials within compromised build environments. We've now crossed that threshold, and the implications are severe.


    The worm's design reveals sophisticated threat modeling. By using Session Protocol for command and control, attackers sidestep traditional network-based detection. By committing exfiltrated data to attacker-controlled GitHub repositories via the GraphQL API, they create a fallback exfiltration channel that persists even if direct C2 connections are discovered. By establishing persistence in developer IDEs, they ensure that each time a developer using a compromised environment loads their editor, the stealer runs again—maximizing the window for credential harvesting across every development session in an organization.


    Most critically, the worm's ability to self-replicate across maintainer packages is a new attack vector that security teams rarely account for. Traditional supply chain defense focuses on protecting package repositories and publisher accounts. This attack goes further: it assumes a published npm token exists with bypass_2fa enabled, finds it, and spreads the worm to other packages under the same maintainer. This transforms a single initial compromise into a cascade of infected packages, each with cryptographically valid provenance.


    For defenders, this incident underscores a hard truth: trust in software artifacts cannot rest on any single verification mechanism. Organizations must adopt defense-in-depth strategies that combine provenance verification, behavioral analysis of dependencies, sandboxed dependency execution in CI/CD pipelines, and aggressive token rotation policies. The days of "update your packages and move on" are over.


    — *HackWire Editorial*


    ## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)