TL;DR AI
Here is the summary:
**What happened:** A security threat actor, TeamPCP, has compromised a series of popular packages, including TanStack, UiPath, Mistral AI, and Guardrails AI, by injecting malware into the npm and PyPI package distribution channels. The malware, disguised as "router_init.js", exfiltrates sensitive data from users' devices, including cloud providers, cryptocurrency wallets, and AI tools.
**Who was affected:** The compromised packages are part of a recent wave of supply chain attacks, and 42 packages and 84 versions are impacted across the TanStack ecosystem.
**Why it matters:** The exploit has been assigned a CVE-2026-45321 and carries a CVSS score of 9.6, indicating critical severity, making it a significant threat to users' data and security.