Quick Facts
- Hackers released 630 malicious versions across 317 packages in 20 minutes on May 19
- OpenAI and Mistral AI confirmed employee devices were compromised but no user data affected
- Attack earned CVE-2026-45321 with critical 9.6 CVSS score and first npm worm with valid security attestations
Cybercriminals compromised hundreds of popular open source packages in an ongoing supply chain attack that security researchers call the most aggressive documented in 2026.
The TeamPCP cybercriminal group took over a developer account and released over 630 malicious versions across 317 packages in about 20 minutes on May 19, according to cybersecurity firms StepSecurity and SafeDep. The attack targeted high-value packages including Antv, a library made by Alibaba.
OpenAI confirmed two employee devices were compromised in the attack but said no user data, production systems, or intellectual property were affected. The company requires all macOS users to update their OpenAI apps before June 12, affecting ChatGPT Desktop, Codex App, Codex CLI, and Atlas.
Mistral AI also confirmed impact from the TanStack supply chain compromise, which led to trojanized versions of its npm and PyPI SDKs. The company said only one developer device was affected.
Critical Security Milestone
The TanStack supply chain compromise earned CVE-2026-45321 with a CVSS score of 9.6 out of 10, indicating critical severity. Security researchers identified it as the first documented npm worm that produces validly-attested malicious packages with valid SLSA Build Level 3 provenance attestations.
The attack hit UiPath’s automation tooling across 65 packages, OpenSearch with 1.3 million weekly npm downloads, and Guardrails AI. TanStack’s React Router package alone accounts for more than 12 million weekly downloads.
Enterprise Impact Grows
Socket CEO Feross Aboukhadijeh warned about the attack’s persistence. “There is no single centralized kill switch for this kind of campaign. The hard part is that by the time a malicious package is confirmed, it may already have been installed inside the exact environments attackers want most: developer machines and CI runners,” he said.
ReversingLabs Co-founder Tomislav Peričin emphasized the strategic targeting. “That’s not a niche library, it’s load-bearing infrastructure for huge swaths of the JavaScript ecosystem, consumed directly and transitively,” he said.
TeamPCP emerged in late 2025 as a cloud-focused cybercriminal group specializing in automating supply-chain attacks and exploiting cloud-native infrastructure. The group announced a supply chain attack contest offering participants $1,000 in Monero to compromise open-source packages using their Shai-Hulud worm.
Immediate Response Required
Security experts recommend organizations immediately rotate CI/CD secrets and access tokens, audit recent installs and dependencies, and investigate anything pulled during the exposure window for signs of compromise.
The attack represents a dangerous evolution in open-source malware, moving from typo-squatted packages to direct compromise of legitimate, highly trusted packages. Security researchers found over 2,000 repositories created using GitHub tokens stolen from compromised CI/CD environments.
Read more: Hackers have compromised dozens of popular open source packages in an ongoing supply chain attack
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
