<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[#ShaiHulud attack ships signed malicious #TanStack, #Mistral #npm packages]]></title><description><![CDATA[<p><a href="https://mastodon.thenewoil.org/tags/ShaiHulud" rel="tag">#<span>ShaiHulud</span></a> attack ships signed malicious <a href="https://mastodon.thenewoil.org/tags/TanStack" rel="tag">#<span>TanStack</span></a>, <a href="https://mastodon.thenewoil.org/tags/Mistral" rel="tag">#<span>Mistral</span></a> <a href="https://mastodon.thenewoil.org/tags/npm" rel="tag">#<span>npm</span></a> packages</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://www.bleepingcomputer.com/news/security/shai-hulud-attack-ships-signed-malicious-tanstack-mistral-npm-packages/" title="Shai Hulud attack ships signed malicious TanStack, Mistral npm packages">
<img src="https://www.bleepstatic.com/content/hl-images/2026/05/05/Hackerbox.jpg" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://www.bleepingcomputer.com/news/security/shai-hulud-attack-ships-signed-malicious-tanstack-mistral-npm-packages/">
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
</a>
</h5>
<p class="card-text line-clamp-3">Hundreds of packages across npm and PyPI have been compromised in a new Shai-Hulud supply-chain campaign delivering credential-stealing malware targeting developers.</p>
</div>
<a href="https://www.bleepingcomputer.com/news/security/shai-hulud-attack-ships-signed-malicious-tanstack-mistral-npm-packages/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://www.bleepstatic.com/favicon/bleeping.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />





<p class="d-inline-block text-truncate mb-0">BleepingComputer <span class="text-secondary">(www.bleepingcomputer.com)</span></p>
</a>
</div></p><p><a href="https://mastodon.thenewoil.org/tags/cybersecurity" rel="tag">#<span>cybersecurity</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/a6f4f532-a407-4720-80ce-011e95b1cddc/shaihulud-attack-ships-signed-malicious-tanstack-mistral-npm-packages</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 05:38:21 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/a6f4f532-a407-4720-80ce-011e95b1cddc.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 13 May 2026 12:30:04 GMT</pubDate><ttl>60</ttl></channel></rss>