Shai-Hulud-Style npm Worm Hits
Reported 29 Jul 2026 by otx · Severity: medium
Multiple npm packages across @tanstack, @mistralai, @uipath, @squawk, and safe-action namespaces were compromised in a worm-like attack affecting over 50 packages. The malicious code executes during installation, downloading the Bun runtime and running a payload that harvests Git