84 TanStack npm Packages Hacked in Ongoing Supply-Chain Attack Targeting CI Credentials

A significant supply-chain compromise affecting 84 npm package artifacts across the TanStack namespace. The malicious versions, published to the npm registry at approximately 19:20 and 19:26 UTC, contain a suspected credential-stealing payload targeting CI systems, including GitHub Actions. According to Socket, the compromise spans 42 TanStack packages — two malicious versions each including widely used […]

The post 84 TanStack npm Packages Hacked in Ongoing Supply-Chain Attack Targeting CI Credentials appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: