TanStack has released a detailed postmortem describing a sophisticated supply-chain attack that compromised 42 npm packages ...
The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the ...
On May 11, 2026, a self-replicating worm called Mini Shai-Hulud quietly slipped into 42 widely used TanStack open-source ...
Shai-Hulud worm exploited GitHub Actions misconfiguration to poison shared cache, now project weighing nuclear option on ...
When OpenAI engineers discovered that a poisoned update to a widely used JavaScript library had executed on two corporate ...
On May 11, 2026, several TanStack packages on npm were briefly replaced with malicious versions, raising fresh concerns about ...
Hundreds of packages across npm and PyPI have been compromised in a new Shai-Hulud supply-chain campaign delivering ...
Over 170 TanStack, Mistral AI, OpenSearch, UiPath, and other packages were affected in a new Mini Shai-Hulud supply chain ...
A new wave of the Mini Shai-Hulud campaign compromised dozens of TanStack npm packages as part of a broader supply chain ...
OpenAI has rotated code-signing certificates after code repositories containing them were compromised in the TanStack supply ...
OpenAI has confirmed two employee devices were affected by the recent TanStack supply chain attack, but stressed the incident ...
TanStack tightens security measures after supply chain attacks. Pull requests may soon only be possible by invitation.