Mass NPM & PyPI Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages

✍️ OpenClawRadar📅 Published: May 12, 2026🔗 Source
Mass NPM & PyPI Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages
Ad

On May 11, 2026, a coordinated supply chain attack compromised over 170 npm packages and 2 PyPI packages across major projects including TanStack, Mistral AI, UiPath, OpenSearch, and Guardrails AI. The attacker published 404 malicious versions total, with some packages receiving up to 9 versions.

High-Profile Targets

  • TanStack (42 packages, 84 versions): Entire router ecosystem including @tanstack/react-router, @tanstack/vue-router, and @tanstack/solid-router alongside their devtools and SSR plugins.
  • Mistral AI (3 npm packages, 9 versions; 1 PyPI package): @mistralai/mistralai (core SDK), @mistralai/mistralai-azure, @mistralai/mistralai-gcp. PyPI package mistralai==2.4.6 (legitimate latest was 2.4.5).
  • UiPath (65 packages) and OpenSearch (1.3M weekly npm downloads).
  • PyPI: guardrails-ai==0.10.1 also compromised.

How the Attack Works

The npm packages contain a malicious preinstall hook that drops files into .claude/settings.json, .claude/setup.mjs, .vscode/tasks.json, and .vscode/setup.mjs. It then uses GitHub's createCommitOnBranch GraphQL mutation to push poisoned configs to the user's repositories, scanning for token patterns ghp_*, gho_*, ghs_*, and npm_*.

The PyPI variant triggers on import (not pip install), downloading a Python dropper from hxxps://git-tanstack[.]com/transformers.pyz and executing it with python3 /tmp/transformers.pyz.

Ad

Indicators of Compromise (IoCs)

  • C2/Exfiltration: hxxp://filev2[.]getsession[.]org/file/
  • AWS metadata probe: hxxp://169[.]254[.]169[.]254/latest/meta-data/iam/security-credentials/
  • Vault probe: hxxp://127[.]0[.]0[.]1:8200
  • Bun runtime download: hxxps://github[.]com/oven-sh/bun/releases/download/bun-v1.3.13/
  • PyPI download domain: hxxps://git-tanstack[.]com/transformers.pyz (Cloudflare-flagged as phishing)

Mitigation

Check your package-lock.json or yarn.lock for the affected versions. Block the listed domains in your firewall. Rotate any tokens that may have been exposed. PyPI has quarantined both mistralai and guardrails-ai projects.

📖 Read the full source: HN AI Agents

Ad

👀 See Also

🦀
Security

Static Analysis of 48 AI-Generated Apps: 90% Had Security Vulnerabilities

A developer scanned 48 public GitHub repos built with Lovable, Bolt, and Replit. 90% had at least one vulnerability. Common issues: auth gaps (44%), SECURITY DEFINER Postgres functions (33%), BOLA/IDOR (25%), and committed secrets (25%).

OpenClawRadar
Audio-Layer Prompt Injection Against Claude: What's Not in the Transcript
Security

Audio-Layer Prompt Injection Against Claude: What's Not in the Transcript

A builder of a prompt injection detection API shares findings on audio-layer attacks against Claude, revealing that attacks in the signal (not transcript) are invisible in logs and pose a real threat to voice agents.

OpenClawRadar
AWS reports AI-augmented attack compromised 600+ FortiGate firewalls
Security

AWS reports AI-augmented attack compromised 600+ FortiGate firewalls

Cybercriminals used off-the-shelf generative AI tools to compromise over 600 internet-exposed FortiGate firewalls across 55 countries in a month-long campaign, according to AWS. The attackers scanned for exposed management interfaces, tried weak credentials, and used AI to generate attack playbooks and scripts.

OpenClawRadar
llm-hasher: Local PII Detection and Tokenization for Hybrid LLM Workflows
Security

llm-hasher: Local PII Detection and Tokenization for Hybrid LLM Workflows

llm-hasher is a tool that detects personally identifiable information locally using Ollama before data reaches external LLMs like OpenAI or Claude, tokenizes the PII, and restores originals after processing. It uses regex for structured data types and a local LLM for contextual detection, with encrypted storage for mappings.

OpenClawRadar