TanStack npm supply-chain attack spreads via Dependabot update

On May 11, 2026, a worm compromised TanStack's release pipeline, publishing 84 malicious versions of 42 packages to npm with valid provenance. The attack leveraged a poisoned cache in a GitHub Actions workflow to steal publishing credentials. Hours later, a Dependabot update automatically pulled two compromised versions into an unrelated aviation-data project. When the maintainer merged the update, the worm used his credentials to publish 110 malicious versions of his own packages. The incident affected over 160 packages ecosystem-wide, including those from Mistral, before being contained.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in