Vulnerabilities · 116 days ago

Valid SLSA Provenance No Longer Guarantees Package Safety

Provenance checks no longer close the trust gap in npm and PyPI. TeamPCP’s Mini Shai-Hulud worm has shown that a package can carry valid SLSA Build Level 3 attestations and still be part of a credential-stealing supply-chain campaign that turns CI/CD systems into distribution nodes.

Tenable says the campaign has compromised more than 170 npm and PyPI packages and breached OpenAI and Mistral AI. The issue is tracked as CVE-2026-45321. The key failure is not just malicious packages, but compromised publishing pipelines that can keep spreading poisoned releases under trusted identities.

That shifts the threat model from bad dependencies to trusted build infrastructure. Any system that installed one of the poisoned packages may need to be treated as fully compromised, because the worm steals developer and cloud credentials and reuses them to seed the next wave.

CVE-2026-45321

NVD KEV

Known exploited · CISA KEV

CVSS 9.6 CRITICAL: on 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. EPSS 2% (81st percentile).

CISA federal remediation date Jun 10

Timeline

Sources

17 sources covering this story

Entities

Part of the PlainSec briefing for 2026-05-18

Editions

Related stories