TanStack NPM Packages Compromised | Hacker News
TL;DR AI
2 min readKey summary
TanStack npm packages were reported compromised in a supply-chain attack.
The suspected path was a CI/CD pipeline breach that exposed publishing secrets or OIDC access.
Attackers may have used that access to push malicious package releases through trusted publishing.
The case underscores that trusted publishing still depends on secure CI and repository credentials.



