TeamPCP’s Mini Shai-Hulud campaign used hijacked GitHub OIDC tokens to spread a credential-stealing worm through TanStack npm ...
TanStack has released a detailed postmortem describing a sophisticated supply-chain attack that compromised 42 npm packages ...
Mini Shai-Hulud hit 2 OpenAI devices via TanStack, exposing limited credentials and forcing macOS certificate updates by June ...
On May 11, 2026, several TanStack packages on npm were briefly replaced with malicious versions, raising fresh concerns about ...
Grafana says hackers compromised business contact information and downloaded its codebase as a result of the TanStack supply ...
The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results