Mini Shai-Hulud
A self-spreading supply chain worm compromised dozens of npm packages, including widely used @tanstack/* router and start packages. Oblique's production builds and CI/CD pipelines were not affected.
What happened?
On May 11, 2026, multiple security vendors reported that an attacker republished compromised versions of more than 50 npm packages, including much of the @tanstack/* router and start family, @uipath/*, and several smaller scopes. The malicious versions smuggled a prepare script via an optionalDependencies entry pointing at an attacker-controlled GitHub commit. On install, the payload exfiltrated GitHub, npm, and cloud credentials over HTTPS, then attempted to publish further compromised versions from any maintainer tokens it found - the "self-spreading" behaviour that mirrored prior Shai-Hulud campaigns.
Oblique depends on several @tanstack/* packages but was pinned below the compromised 1.169.x package version. Our NPM package manager, pnpm, is configured with a 72-hour minimumReleaseAge cooldown, which prevented any version uptake during the window in which the bad releases were live on the registry. As defence in depth, we also rely on pnpm 10's default-deny on dependency lifecycle scripts and our explicit onlyBuiltDependencies allowlist mean that the malicious prepare script could not have executed in our CI runners or developer machines even if a bad version had been resolved.
What was the impact?
We have verified that none of the compromised package versions were ever resolved or installed in our production builds, CI/CD pipelines, or developer environments. No Oblique credentials or source were exposed.
Who was affected?
Neither Oblique nor any Oblique customers are affected.
What do I need to do?
No action is required from Oblique customers.