
Postmortem: TanStack npm supply-chain compromise
SupplyChainCybersecurityMalwareIncidentResponsenpmTanStackAccountCompromiseSecurityBreach
The TanStack team reported an npm supply-chain compromise where an attacker gained access to their npm publishing account. The incident involved unauthorized versions of packages being published, which included malicious code. The team identified the breach, revoked the compromised credentials, and released clean versions of affected packages. They also implemented additional security measures to prevent future incidents.