GeistHaus
log in · sign up

Postmortem: TanStack npm supply-chain compromise | TanStack Blog

javascriptweekly.com

On 2026-05-11, an attacker chained a pull_request_target Pwn Request, GitHub Actions cache poisoning across the fork↔base trust boundary, and OIDC token extraction from runner memory to publish 84 malicious versions across 42 @tanstack/* packages on npm. Full postmortem.

0 pages link to this URL

No pages have linked to this URL yet.