Shai-Hulud-Style npm Worm Hits

Reported 29 Jul 2026 by otx · Severity: medium

Multiple npm packages across @tanstack, @mistralai, @uipath, @squawk, and safe-action namespaces were compromised in a worm-like attack affecting over 50 packages. The malicious code executes during installation, downloading the Bun runtime and running a payload that harvests Git