TeamPCP TanStack Supply Chain Attack
UltraViolet Cyber
pdf
2026-05-20T00:00:00
Abstract
On 11 May 2026, the threat actor group TeamPCP compromised 42 TanStack npm packages by chaining three GitHub Actions vulnerabilities to hijack the project's legitimate CI/CD pipeline. The attackers then published 84 malicious package versions carrying valid SLSA Build Level 3 provenance attestations, making them indistinguishable from legitimate releases by standard verification methods. The payload, a variant of TeamPCP's Mini Shai-Hulud credential-stealing worm, propagated autonomously by using harvested npm tokens to infect additional packages, ultimately reaching over 170 packages and 400 malicious versions across npm and PyPI within five hours.
Loading executive summary...
Loading full markdown...
Match Rate:
10.00/10
(Relevance to core cybersecurity goals)