Mini Shai-Hulud worm hits TanStack, Mistral AI, and 170+ npm/PyPI packages
A supply chain attack compromised TanStack packages and spread to Mistral AI SDK, Guardrails AI, OpenSearch, targeting AI dev tools to steal credentials. Malicious versions used signed provenance to appear legitimate, prompting urgent credential rotations.