# Backdoored Cemu release linked to TanStack and Mistral supply chain campaign

DevFeed: [Backdoored Cemu release linked to TanStack and Mistral supply chain campaign](<https://devfeed.tech/articles/backdoored-cemu-release-linked-to-tanstack-and-mistral-supply-chain-campaign-8277.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/backdoored-cemu-release-teampcp-supply-chain-campaign/>)

Author: Martin McCloskey, Sebastian Obregoso, Rory McCune

Published: 2026-05-14T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Python](<https://devfeed.tech/topics/python.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [payload](<https://devfeed.tech/topics/payload.md>), [REST API](<https://devfeed.tech/topics/rest-api.md>), [releases](<https://devfeed.tech/topics/releases.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [github](<https://devfeed.tech/tags/github.md>), [linux](<https://devfeed.tech/tags/linux.md>), [payload](<https://devfeed.tech/tags/payload.md>), [python](<https://devfeed.tech/tags/python.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

## AI overview

A coordinated supply chain campaign compromised npm and PyPI packages and backdoored the official Cemu GitHub release. The malicious Linux AppImage reached nearly 20,000 users before detection, while investigation linked the payload across the affected ecosystems.

## Source excerpt

We investigate how a coordinated supply chain campaign that compromised npm and PyPI packages also backdoored the official Cemu Nintendo Wii U emulator GitHub release, reaching nearly 20,000 Linux users.