TeamPCP, the threat actor behind the recent supply chain
attack spree, has been linked to the compromise of the npm and PyPI
packages from TanStack, UiPath, Mistral AI, OpenSearch, and
Guardrails AI as part of a fresh Mini Shai-Hulud campaign. The
affected npm packages have been modified to include an obfuscated
JavaScript file ("router_init.js") that's designed to profile the
execution
Read more https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html

