On May 11, 2026, a worm published 84 malicious versions of 42 TanStack packages to npm, with valid provenance, from TanStack's own release pipeline. Two and a half hours later a Dependabot pull request pulled two of those versions into a small aviation-data project, and a single merge turned its maintainer's publish token into 110 more malicious... Weiterlesen: TanStack npm supply-chain attack: how a Dependabot bump spread a worm
Intelligence View
⚡ tsecurity.de Intelligence
TanStack npm supply-chain attack: how a Dependabot bump spread a worm
On May 11, 2026, a worm published 84 malicious versions of 42 TanStack packages to npm, with valid provenance, from TanStack's own release pipeline. Two and a…