Switch language한국어
Back to the list

TanStack NPM Packages Compromised | Hacker News

TL;DR AI

Key summary

2 min read
  1. TanStack npm packages were reported compromised in a supply-chain attack.

  2. The suspected path was a CI/CD pipeline breach that exposed publishing secrets or OIDC access.

  3. Attackers may have used that access to push malicious package releases through trusted publishing.

  4. The case underscores that trusted publishing still depends on secure CI and repository credentials.

Read the original