Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
… According to supply-chain security platform SafeDep, although the trigger mechanism is different in compromised Mistral AI and TanStack packages, they drop the same credential-stealing payload. …