Cache-poisoning caper turns TanStack npm packages toxic

Source: The Register (Security)  ·  Category: Supply Chain


TanStack npm package supply chain compromised; 84 malicious versions injected in six minutes with credential theft and destructive payloads. Law firms using TanStack dependencies or npm packages broadly must audit build pipelines for infection and assess code review practices.

→ Read the full article

Read more