people · May 16, 2026
Supply Chain Attack Affects UiPath Packages
Share the canonical public link.
A supply chain worm injected credential-stealing malware into over 170 packages across TanStack, Mistral AI, Guardrails AI, and UiPath on May 15, 2026. The attack abuses GitHub Actions and OIDC workflows to steal GitHub tokens, cloud credentials, npm tokens, and CI/CD secrets. Researchers identified persistence mechanisms and destructive wiper behavior on infected systems. The malware campaign spans hundreds of malicious package versions.
Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)