Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
•
AI & KI NachrichtenHacking Without Boundaries - Michael Jenkins - PSW #946(01.10.2026 um 23:00 Uhr)
•••
Sicherheitslücken (CVE)Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation(01.10.2026 um 16:17 Uhr)
••
Malware / Trojaner / VirenAlleged KillSec Ransomware Mastermind a 16-Year-Old(01.10.2026 um 23:37 Uhr)
•
IT Security NachrichtenDenial of Service in gnome-shell (SUSE)(01.10.2026 um 22:37 Uhr)
•
IT Security NachrichtenDenial of Service in rpcbind (SUSE)(01.10.2026 um 22:37 Uhr)
•
IT Security NachrichtenDenial of Service in libXpm (Ubuntu)(01.10.2026 um 22:37 Uhr)
••
AI & KI NachrichtenHacking Without Boundaries - Michael Jenkins - PSW #946(01.10.2026 um 23:00 Uhr)
•••
Sicherheitslücken (CVE)Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation(01.10.2026 um 16:17 Uhr)
••
Malware / Trojaner / VirenAlleged KillSec Ransomware Mastermind a 16-Year-Old(01.10.2026 um 23:37 Uhr)
•
IT Security NachrichtenDenial of Service in gnome-shell (SUSE)(01.10.2026 um 22:37 Uhr)
•
IT Security NachrichtenDenial of Service in rpcbind (SUSE)(01.10.2026 um 22:37 Uhr)
•
IT Security NachrichtenDenial of Service in libXpm (Ubuntu)(01.10.2026 um 22:37 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

TanStack npm supply-chain attack: how a Dependabot bump spread a worm

On May 11, 2026, a worm published 84 malicious versions of 42 TanStack packages to npm, with valid provenance, from TanStack's own release pipeline. Two and a…

Beitrag
0
Seite
0
↗ Quelle (DEV Community)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

On May 11, 2026, a worm published 84 malicious versions of 42 TanStack packages to npm, with valid provenance, from TanStack's own release pipeline. Two and a half hours later a Dependabot pull request pulled two of those versions into a small aviation-data project, and a single merge turned its maintainer's publish token into 110 more malicious... Weiterlesen: TanStack npm supply-chain attack: how a Dependabot bump spread a worm

Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag