As cited
Copy frozen at (site build).
threat intel
Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised
Malicious npm packages linked to the Mini Shai-Hulud supply chain campaign have compromised TanStack and additional developer tooling packages. The attack targets high-value dependencies that could expose downstream projects to compromise through software supply chain pollution.
Why it matters: Development teams relying on affected npm packages face immediate risk of code injection and malware distribution to their applications and users; practitioners should audit dependencies and update to verified clean versions.
- Source published
- First seen by Cybersecurity Tracker