TeamPCP TanStack Supply Chain Attack

UltraViolet Cyber pdf 2026-05-20T00:00:00

Abstract

On 11 May 2026, the threat actor group TeamPCP compromised 42 TanStack npm packages by chaining three GitHub Actions vulnerabilities to hijack the project's legitimate CI/CD pipeline. The attackers then published 84 malicious package versions carrying valid SLSA Build Level 3 provenance attestations, making them indistinguishable from legitimate releases by standard verification methods. The payload, a variant of TeamPCP's Mini Shai-Hulud credential-stealing worm, propagated autonomously by using harvested npm tokens to infect additional packages, ultimately reaching over 170 packages and 400 malicious versions across npm and PyPI within five hours.

Loading executive summary...
Loading full markdown...

Your browser does not support inline PDF viewing.

Download the PDF to view it.

Match Rate: 10.00/10 (Relevance to core cybersecurity goals)

LINK COPIED TO CLIPBOARD