Mini Shai-Hulud npm and PyPI Worm: How TeamPCP Hijacked TanStack, AntV, and OIDC Trusted Publishing in May 2026 (Developer Defense Guide)
In May 2026 the Mini Shai-Hulud worm compromised 84 @tanstack packages in 6 minutes and 300+ @antv-adjacent versions in 22 minutes by exploiting npm OIDC trusted publishing. Even maintainers with 2FA, short-lived tokens, and signed provenance got hit. Here is what actually broke, what I changed in my CI pipelines across seven aggregator sites, and a 9-step lockdown plan for your npm and PyPI workflow.