Vulnerabilities & Exploits · Supply Chain

Valid SLSA Provenance No Longer Guarantees Package Safety

Provenance checks no longer close the trust gap in npm and PyPI. TeamPCP’s Mini Shai-Hulud worm has shown that a package can carry valid SLSA Build Level 3 attestations and still be part of a credential-stealing supply-chain campaign that turns CI/CD systems into distribution nodes.

Tenable says the campaign has compromised more than 170 npm and PyPI packages and breached OpenAI and Mistral AI. The issue is tracked as CVE-2026-45321. The key failure is not just malicious packages, but compromised publishing pipelines that can keep spreading poisoned releases under trusted identities.

That shifts the threat model from bad dependencies to trusted build infrastructure. Any system that installed one of the poisoned packages may need to be treated as fully compromised, because the worm steals developer and cloud credentials and reuses them to seed the next wave.

17 sources · May 21

Community Assessment

Threat researchers from SANS and Unit 42 describe TeamPCP’s campaign as evolving into wormable propagation with infrastructure persistence and monetization, broadening beyond the headline package compromise and indicating operational maturity before the current report.

CVE-2026-45321

NVD KEV

Known exploited · CISA KEV

CVSS 9.6 CRITICAL: on 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. EPSS 2% (81st percentile).

CISA federal remediation date Jun 10

Timeline

Sources

Part of the PlainSec briefing for 2026-05-18

Every edition of this story: Valid SLSA Provenance No Longer Guarantees Package Safety

More from today