SENTINEL
GLOBAL technology · severity 7

npm Supply Chain Vulnerability: TanStack Package Contamination with Malware

Supply chain security breach: malicious actors pushed 84 poisoned versions of TanStack npm packages in a six-minute window, containing credential theft and disk-wiping code. The incident highlights ongoing vulnerability of the npm ecosystem to coordinated package contamination attacks.

Sources

← Back to this edition