Menu

Post image 1
Post image 2
Post image 3
Post image 4
Post image 5
Post image 6
Post image 7
Post image 8
Post image 9
Post image 10
Post image 11
Post image 12
Post image 13
1 / 13
0

Cache-poisoning caper turns TanStack npm packages toxic

theregister·Tim Anderson·20 days ago
#IuHvdWvs
Reading 0:00
15s threshold

Cyber-Crime Six-minute supply chain blitz pushed 84 malicious versions with credential theft and disk-wiping code An attacker has published 84 malicious versions of official TanStack npm packages, with the impact including credential theft, self-propagation, and complete disk wipe of an infected host. The attack is part of a wave of attacks across npm and PyPI, continuing the Mini Shai-Hulud campaign . Supply chain security company Socket reports  that other compromised packages include the OpenSearch client, Mistral AI, UiPath, and Guardrails AI. Malicious npm packages for TanStack, an open source application stack, were published between 19:20 and 19:26 UTC on May 11. The attack was detected and reported  within 30 minutes by StepSecurity, triggering incident response and npm deprecation. GitHub published a security advisory  at 21:30 UTC, including a list of affected packages.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More