This is a supply chain compromise where malicious versions of npm packages were published, not a vulnerability in internet-facing applications. The threat is to development environments and CI/CD pipelines that download these packages, not to production servers.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: OTHER
CVE Published: 2026-05-12
Added to CISA KEV: 2026-05-27 15 DAYS BETWEEN CVE AND KEV
CVE-2026-45321 is a critical supply chain vulnerability (CVSS 9.6) associated with a campaign identified as "Mini Shai-Hulud," which involved the unauthorized publication of malicious packages to the npm and PyPI registries in May 2026 [1].
Here is the breakdown of the requested information:
Microsoft Threat Intelligence confirmed on May 12, 2026 that mistralai PyPI package v2.4.6 had been compromised as part of the Mini Shai-Hulud supply chain campaign. The campaign entry point has been assigned CVE-2026-45321 (CVSS 9.6). ... Between May 11 and 12, 2026, threat actors published over 40โฆ
On May 11, 2026, threat actors executed a multi-stage supply chain attack against the @tanstack ecosystem. By exploiting a pull_request_target misconfiguration in GitHub Actions, attackers poisoned build caches and extracted OIDC tokens from memory. This allowed the unauthorized publication of 84 maโฆ
The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow ... ... Information Technology Laboratory National Vulnerability Database Vulnerabilities ... National Vulnerability Database. Vulnerabilities. CVE-2026-453โฆ