Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 16, 2026 (about 4 months ago).

people · May 16, 2026

Supply Chain Attack Affects UiPath Packages

Share the canonical public link.

Share as image

A supply chain worm injected credential-stealing malware into over 170 packages across TanStack, Mistral AI, Guardrails AI, and UiPath on May 15, 2026. The attack abuses GitHub Actions and OIDC workflows to steal GitHub tokens, cloud credentials, npm tokens, and CI/CD secrets. Researchers identified persistence mechanisms and destructive wiper behavior on infected systems. The malware campaign spans hundreds of malicious package versions.

Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)

Supporting evidence