Cointime

Download App
iOS & Android

Mini Shai-Hulud Worm Affects TanStack, OpenSearch, and Mistral Clients

According to monitoring by Dongcha Beating, a worm named 'Mini Shai-Hulud' (the sandworm from 'Dune') is sweeping through the front-end and AI back-end ecosystems. The attacker TeamPCP hijacked the official release pipeline of TanStack between 3:20 and 3:26 AM (UTC+8) on May 12, pushing 84 malicious versions of 42 official packages to npm, including the widely downloaded `@tanstack/react-router`. The worm subsequently spread to PyPI, with the latest victims including Amazon's `@opensearch-project/opensearch` (npm, 1.3 million weekly downloads), the official Mistral client `mistralai`, and the AI guard tool `guardrails-ai` (both on PyPI). The malicious packages appear identical to legitimate releases. The attackers did not steal any long-term credentials but exploited a GitHub Actions configuration vulnerability to hijack the official pipeline, gaining legitimate temporary release permissions. As a result, the malicious packages received authentic SLSA build source signatures (provenance, a type of anti-counterfeiting label that proves 'the package was indeed produced by the official pipeline'). The developers' previously trusted logic of 'signed = safe' has been completely bypassed. Worse, uninstalling the malicious packages is far from sufficient. Reverse analysis by Socket.dev shows that once the worm is installed, it writes itself into the execution hooks of Claude Code (`.claude/settings.json`) and the task configuration of VS Code (`.vscode/tasks.json`). Even if the malicious packages are deleted, as long as the developer later opens the project directory or wakes up the AI assistant, the malicious code will automatically reactivate. The threshold for triggering on the Python side is even lower: developers don't even need to call any functions; simply `importing` the infected package will silently activate the spying. TeamPCP mockingly posted a message on the spoofed domain `git-tanstack[.]com` saying, 'We have been online stealing credentials for over two hours, but I'm just here to say hello :^)'. The worm continues to self-propagate. Machines that installed the affected packages during the aforementioned window should be treated as compromised: immediately rotate all credentials for AWS, GitHub, npm, SSH, etc., thoroughly check the `.claude/` and `.vscode/` directories, and reinstall from a clean lockfile.

Comments

All Comments

Recommended for you

  • Saudi Arabia Depletes 86% of Patriot Missile Stockpile

    According to British media reports, within the first 38 days after the outbreak of the war, Saudi Arabia launched approximately 2,400 PAC-3 (Patriot-3) interceptor missiles, accounting for about 86% of the country's total stockpile of 2,800 missiles. By April of last year, Saudi Arabia had only about 400 interceptor missiles remaining. Other Gulf Arab states also consumed missile reserves on a similar scale, highlighting the military crisis facing the region. (Jin Shi)
  • Experts: The Strait of Hormuz 'Will Never' Return to Pre-War Status

    Ali Akbar Dareini, a researcher at the Iranian Strategic Studies Center, stated that Iran and Oman are about to reach an agreement on the future management of the Strait of Hormuz, with the main obstacle being U.S. pressure on Oman to adopt a position more aligned with Washington. Dareini emphasized that Iran considers future control of the strait crucial for its national security. In recent months, the U.S. has conducted strikes against Iran, which Iran claims were launched from bases in the region. Dareini noted that the ongoing negotiations between Iran and Oman present the U.S. with a 'good opportunity to extricate itself from this quagmire' by recognizing Iran and Oman as the countries that will determine the 'future' of the Strait of Hormuz. 'However, the Strait of Hormuz will never return to its pre-war status,' he continued. 'The geopolitical landscape of the region has changed.'
  • Iran: Negotiations with Oman Unrelated to Reopening of Strait of Hormuz

    On August 8, a spokesperson for the Islamic Revolutionary Guard Corps of Iran stated that the reopening of the Strait of Hormuz is unrelated to negotiations between Iran and Oman, but rather depends on whether the United States fully accepts Iran's conditions and ceases interference in regional negotiations. "Once the United States accepts Iran's conditions, the Strait will undoubtedly reopen." (CCTV News)
  • Whale Shorting $102 Million in Bitcoin Faces Partial Liquidation, Remaining Liquidation Price Around $65,300

    On August 8, TheDataNerd reported that a whale using 40x leverage to short $102 million in Bitcoin recently faced partial liquidation, incurring a loss of $1.46 million over the past week. Currently, the margin call has reduced the short position to approximately $60 million, with an opening price of $64,212.5 and a liquidation price of $65,310.2.
  • BTC Falls Below $65,000

    Market data shows BTC has fallen below $65,000, currently reported at $64,999.23, with a 24-hour increase of 1.01%. Market volatility is high, please exercise risk control.
  • Hedge Fund AISituational Awareness's Mysterious $400 Million Investment Targets Chip Startup Source Foundry

    On August 8, sources revealed that the hedge fund Situational Awareness, managed by former OpenAI researcher Leopold Aschenbrenner, made a mysterious $400 million investment in the chip manufacturing startup Source Foundry just days after facing imminent collapse. Previously, Bloomberg reported that the hedge fund invested in a private company backed by Sequoia Capital, but did not disclose the name of the specific company. The Wall Street Journal had earlier reported that the recipient of the investment was Source Foundry, unveiling the target of this mysterious funding deployment by Situational Awareness.
  • US Spot Bitcoin ETF Sees $101.79M Net Inflow Yesterday

    On August 8, according to Trader T's monitoring, US spot bitcoin ETFs saw a net inflow of $101.79 million yesterday.
  • US Official: Ukraine Agrees to Avoid Strikes on Non-Russian Tankers and Black Sea Oil Facilities

    On August 8, according to a US official, Ukraine has agreed not to target certain non-Russian tankers and Black Sea infrastructure vital to Kazakhstan's crude oil exports. This follows ship attacks last month that caused loading disruptions. The US official said Ukraine has set up contact points so commercial shipping companies can communicate information and ensure safe passage. The commitment was reached after meetings between senior US government leaders and Ukrainian leadership, marking a potentially significant step toward increasing regional oil shipments. Previously, activity in the region had cooled significantly due to several recent attacks near the Caspian Pipeline Consortium terminal in Russia's Novorossiysk. (Jin Shi)
  • U.S. July Nonfarm Payrolls Fall by 23,000, Missing Market Expectations

    On August 7, U.S. nonfarm payrolls decreased by 23,000 in July, compared with market expectations of an increase of 80,000, and the previous value was an increase of 57,000.