Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
tanscript-exploit-check — IOC checker for the TanStack/Mini Shai-Hulud npm supply chain attack (CVE-2026-45321) | Kitploit
Tools/GitHubGitHub/nkopylov/tanscript-exploit-check
Indicator of Compromise (IOC) ManagementVulnerability AnalysisForensicsThreat IntelligenceSupply Chain SecurityIncident Response
GitHubnkopylov/tanscript-exploit-check

tanscript-exploit-check

IOC checker for the TanStack/Mini Shai-Hulud npm supply chain attack (CVE-2026-45321)

View Repository
1174 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Mini Shai-Hulud Supply Chain Attack — IOC Checker

curl -fsSL https://raw.githubusercontent.com/nkopylov/tanscript-exploit-check/main/check-tanstack-exploit.sh | bash

Or clone and run locally:

git clone https://github.com/nkopylov/tanscript-exploit-check.git
cd tanscript-exploit-check
./check-tanstack-exploit.sh [project_dir ...]

What happened

This checker covers two waves of the Mini Shai-Hulud supply chain attack campaign by TeamPCP:

Wave 1: TanStack CI/CD Compromise (May 11, 2026)

On May 11, 2026 (19:20-19:26 UTC), an attacker published 84 malicious versions across 42 @tanstack/* npm packages in a 6-minute window. The attack also hit packages from Mistral AI, UiPath, OpenSearch, and others — over 170 packages total across npm and PyPI.

No maintainer credentials were stolen. The attacker exploited the CI/CD trust chain itself via a 3-stage attack:

  1. pull_request_target exploit — A throwaway GitHub fork opened a PR that ran attacker code in the base repo's security context
  2. GitHub Actions cache poisoning — The fork's code poisoned the shared pnpm cache, which later infected legitimate release workflows
  3. OIDC token extraction from process memory — The malicious code extracted npm publish tokens directly from the GitHub Actions runner's memory, producing packages with valid SLSA Build Level 3 provenance attestations

Wave 2: "atool" npm Account Takeover (May 19, 2026)

On May 19, 2026 (01:39-02:06 UTC), the compromised atool npm account ([email protected]) published 637 malicious versions across 314 packages in two automated waves. High-impact targets include:

  • size-sensor (4.2M downloads/month)
  • echarts-for-react (3.8M downloads/month)
  • @antv/scale (2.2M downloads/month)
  • timeago.js (1.15M downloads/month)
  • 310+ additional @antv/* and other packages

This wave used a Bun-based payload (498KB index.js) triggered via "preinstall": "bun run index.js", with a second-stage payload hidden in imposter commits pushed to the antvis/G2 GitHub repo via the fork object sharing exploit.

What the malicious code does (both waves)

Both waves use the same "Mini Shai-Hulud" toolkit family:

  • Credential harvesting: 80+ env vars, AWS full chain (env → config → IMDSv2 → ECS → Secrets Manager), GitHub PATs, npm tokens, SSH keys, K8s tokens, Vault tokens, password managers (1Password, Bitwarden, pass, gopass)
  • Persistence: gh-token-monitor (Wave 1) and kitty-monitor (Wave 2) daemons via LaunchAgent/systemd; hooks in .claude/settings.json and .vscode/tasks.json
  • Exfiltration: P2P networks (Wave 1), GitHub Git Data API + HTTPS disguised as OpenTelemetry traces (Wave 2)
  • CI/CD abuse: Workflow injection dumping toJSON(secrets), npm OIDC token exchange
  • Dead-man's switch: rm -rf ~/ if GitHub token revoked while daemon active
  • Dead-drop C2 (Wave 2): Polls GitHub commit search API for firedalazer keyword, RSA-PSS signed commands

What this script checks

#CheckDescription
1Dead-man's switchPersistence daemons: gh-token-monitor (Wave 1), kitty-monitor (Wave 2)
2Malicious processesKnown attacker process names (both waves)
3Payload filesKnown malicious files by name and SHA-256 hash (4 hashes)
4Claude Code hooksInjected hooks in .claude/settings.json + generic SessionStart heuristic
5VS Code tasksInjected tasks in .vscode/tasks.json + generic runOn: folderOpen heuristic
6GitHub ActionstoJSON(secrets) in any workflow + pull_request_target warning
7npm lockfilesCompromised package versions in lockfiles
8optionalDependenciesMalicious @tanstack/setup and @antv/setup + 4 imposter commit SHAs
9Network connectionsActive connections to C2 infrastructure (5 domains/IPs)
10DNS cachePrior resolution of attacker domains (4 domains)
11Git branchesDune-themed attacker branch naming pattern
12Lifecycle scriptsHeuristic: bun run in preinstall/postinstall (installed packages)
13Dead-drop C2firedalazer keyword and "Shai-Hulud" markers in git history
14GitHub depsHeuristic: github: dependencies pinned to commit SHA in optionalDeps

Affected packages

Wave 1: TanStack (42 packages)

Only @tanstack/router* and @tanstack/start* were affected. NOT affected: @tanstack/query*, @tanstack/table*, @tanstack/form*, @tanstack/virtual*, @tanstack/store.

PackageMalicious versionsFirst safe version
@tanstack/react-router1.169.5, 1.169.81.169.9
@tanstack/router-core1.169.5, 1.169.81.169.9
@tanstack/vue-router1.169.5, 1.169.81.169.9
@tanstack/solid-router1.169.5, 1.169.81.169.9
@tanstack/react-start1.167.68, 1.167.711.167.72
@tanstack/router-plugin1.167.38, 1.167.411.167.42

See the full advisory for all 42 packages.

Wave 2: atool account (314 packages)

All packages published by npm user atool ([email protected]) received malicious versions on May 19, 2026. High-impact packages include:

PackageMonthly downloads
size-sensor4.2M
echarts-for-react3.8M
@antv/scale2.2M
timeago.js1.15M

Plus 310+ packages primarily in the @antv/* scope (@antv/g2, @antv/g6, @antv/l7, @antv/s2, @antv/x6, @antv/f2, etc.), ai-figure, timeago-react, jest-canvas-mock, jest-date-mock, and others.

See the SafeDep writeup for the full list.

Remediation (if compromised)

CRITICAL: Disable the dead-man's switch BEFORE revoking any tokens. The malware wipes $HOME if tokens are revoked while the daemon is active.

  1. Kill persistence daemons (gh-token-monitor AND kitty-monitor) and remove LaunchAgent/systemd services
  2. Remove persistence files (.claude/router_runtime.js, .vscode/setup.mjs, ~/.local/share/kitty/cat.py, /var/tmp/.gh_update_state, etc.)
  3. Delete node_modules and lockfiles, reinstall with --ignore-scripts
  4. Rotate ALL credentials (npm, GitHub, AWS, GCP, SSH keys, Vault tokens, password manager tokens, etc.)
  5. Block attacker domains at DNS/firewall level (api.masscan.cloud, filev2.getsession.org, git-tanstack.com, t.m-kosche.com)
  6. Audit cloud provider logs for May 11-19, 2026

Official announcements and references

Wave 1: TanStack (May 11)

  • CVE-2026-45321 (CVSS 9.6 Critical) — CVE Record
  • GHSA-g7cv-rxg3-hmpx — GitHub Advisory
  • TanStack Postmortem — tanstack.com/blog/npm-supply-chain-compromise-postmortem
  • TanStack Hardening Follow-up — tanstack.com/blog/incident-followup
  • GitHub Tracking Issue — TanStack/router#7383

Wave 2: atool account takeover (May 19)

  • SafeDep Analysis — safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised

Security researcher write-ups

Download Tool