TanStack, the popular open source JavaScript library ecosystem, is considering restricting pull requests to invitation-only contributors following a supply chain attack. The Shai-Hulud worm exploited a GitHub Actions misconfiguration to poison a shared cache, prompting the project to weigh drastic measures against unsolicited external contributions.

4m read timeFrom theregister.com
Post cover image
Table of contents
OpenAI caught in TanStack npm supply chain chaos after employee devices compromisedCache-poisoning caper turns TanStack npm packages toxicMalware crew TeamPCP open-sources its Shai-Hulud worm on GitHubThe never-ending supply chain attacks worm into SAP npm packages, other dev toolsGrafana Labs admits all its codebase are belong to someone who popped its GitHub account
393 Impressions