<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>KB-2382 Information about the Axios Supply Chain Compromise</title><link>https://community.appian.com/support/w/kb/3810/kb-2382-information-about-the-axios-supply-chain-compromise</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>KB-2382 Information about the Axios Supply Chain Compromise</title><link>https://community.appian.com/support/w/kb/3810/kb-2382-information-about-the-axios-supply-chain-compromise</link><pubDate>Wed, 13 May 2026 20:18:13 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:d49276b2-ef34-4bae-a832-6fb52350b0d5</guid><dc:creator>Kaushal Patel</dc:creator><comments>https://community.appian.com/support/w/kb/3810/kb-2382-information-about-the-axios-supply-chain-compromise#comments</comments><description>Current Revision posted to Appian Knowledge Base by Kaushal Patel on 5/13/2026 8:18:13 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 11 May 2026, a coordinated supply chain attack was launched against the npm and PyPI ecosystems, targeting high-value developer tools and enterprise platforms. The campaign compromised a wide range of popular packages, including the @tanstack namespace (such as &lt;/span&gt;&lt;span style="font-weight:400;"&gt;@tanstack/react-router&lt;/span&gt;&lt;span style="font-weight:400;"&gt;), the official mistralai clients for TypeScript and Python, and AI safety tools like guardrails-ai.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian has investigated this vulnerability and affected services, and determined that it is &lt;/span&gt;&lt;b&gt;not impacted&lt;/b&gt;&lt;span style="font-weight:400;"&gt;, as no vulnerable versions of the packages are used in the Appian Cloud environment or any of Appian&amp;rsquo;s products. We will continue to monitor the situation and provide any updates as appropriate.&lt;/span&gt;&lt;/p&gt;
&lt;h2 id="mcetoc_1jl7jgb3u1"&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised"&gt;&lt;span style="font-weight:400;"&gt;https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack"&gt;&lt;span style="font-weight:400;"&gt;https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised"&gt;&lt;span style="font-weight:400;"&gt;https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="mcetoc_1jl7jgb3u2"&gt;&lt;span&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Last reviewed:&amp;nbsp;&lt;/span&gt;&lt;span&gt;May 13, 2026&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item></channel></rss>