Shai Hulud Malware Compromises TanStack, OpenAI, and Mistral AI in Sprawling Supply-Chain Attack
A sophisticated AI supply-chain attack linked to the TeamPCP threat group has compromised hundreds of software packages across TanStack, Mistral AI, and OpenAI. The Shai Hulud malware exploited developer infrastructure to steal credentials from GitHub, cloud providers, and CI/CD systems. The self-propagating worm published 84 malicious versions with valid security attestations, exposing critical gaps in how AI companies secure their release pipelines.