---
title: "TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack"
url: https://stacklist.com/card/ff9999df-159a-4067-8ac9-32d144b2f000
source_url: "https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack"
stack: https://stacklist.com/c/finance/stack/4e9a6b47-d2ca-4b21-8344-f70c4f000e5e
summary: "TrapDoor crypto stealer is a supply chain attack that compromised 36 malicious packages across npm, PyPI, and Crates.io, targeting developers working in crypto, DeFi, AI, and security. The attack, discovered by the Socket Research Team, affected hundreds of package versions across multiple open-source ecosystems."
tags: "supply-chain-attack, crypto-stealer, npm, pypi, crates-io, malware, open-source-security"
key_entities: "TrapDoor Crypto Stealer (concept), Socket Research Team (organization), npm (technology), PyPI (technology), Crates.io (technology), supply-chain attack (concept), DeFi (concept)"
classification: "analysis"
content_hash: "sha256:88a2caec80e70a653b909a40a98cb6e07a81514491fcf2c112744966f213532b"
acp_version: "0.2"
token_counts_approximate: 80
visibility: public
agent_accessible: true
status: "final"
---

# TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack

Research / Security News TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io TrapDoor crypto stealer hits 36 malicious packages across npm, PyPI, and Crates.io, targeting crypto, DeFi, AI, and security developers. By Socket Research Team - May 24, 2026
