TanStack, the popular open source JavaScript library ecosystem, is considering restricting pull requests to invitation-only contributors following a supply chain attack. The Shai-Hulud worm exploited a GitHub Actions misconfiguration to poison a shared cache, prompting the project to weigh drastic measures against unsolicited external contributions.
Table of contents
OpenAI caught in TanStack npm supply chain chaos after employee devices compromisedCache-poisoning caper turns TanStack npm packages toxicMalware crew TeamPCP open-sources its Shai-Hulud worm on GitHubThe never-ending supply chain attacks worm into SAP npm packages, other dev toolsGrafana Labs admits all its codebase are belong to someone who popped its GitHub account393 Impressions