A self-propagating worm dubbed Mini Shai-Hulud, attributed to the threat actor TeamPCP (tracked as UNC6780 by Google), compromised more than 170 npm and PyPI packages with a cumulative 518 million weekly downloads, including 84 malicious versions across 42 TanStack packages. The campaign stole developer and cloud credentials via CI/CD pipelines and extracted OIDC tokens from GitHub Actions runners, allowing malicious package versions to carry valid SLSA Build Level 3 cryptographic provenance attestations, a security control that was assumed to prevent exactly this kind of tampering. Affected organizations included OpenAI, Mistral AI, GitHub, and the European Commission, with at least 400 new GitHub repositories created as part of the campaign’s infrastructure.