The Biggest npm Security Breach of 2026 Explained: TanStack, Mini Shai-Hulud, and OpenAI

In 6 minutes, attackers published 84 malicious npm packages via TanStack’s own pipeline. Here’s how Mini Shai-Hulud worked, and what OpenAI found when it checked its systems.




