⤷ Title: “TanStack”: Malicious Name-Squatting Campaign Steals Environment Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 02:58:40 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #cybersecurity #data exfiltration #DevSecOps #infosec #npm malware #Postinstall Script #supply chain attack #Svix #TanStack #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 02:58:40 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #cybersecurity #data exfiltration #DevSecOps #infosec #npm malware #Postinstall Script #supply chain attack #Svix #TanStack #Typosquatting
Daily CyberSecurity
"TanStack": Malicious Name-Squatting Campaign Steals Environment Secrets
A malicious unscoped "tanstack" npm package used live-debugged postinstall scripts to steal .env secrets via Svix webhooks. Check your dependencies now.
⤷ Title: Supply Chain Siege: 84 TanStack Packages Compromised to Steal GitHub Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:37:03 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack/react_router #CI/CD security #credential stealer #GitHub Actions #infosec #JavaScript Security #Malware Analysis #npm Security #Socket Threat Research #supply chain attack #TanStack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:37:03 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack/react_router #CI/CD security #credential stealer #GitHub Actions #infosec #JavaScript Security #Malware Analysis #npm Security #Socket Threat Research #supply chain attack #TanStack
Daily CyberSecurity
Supply Chain Siege: 84 TanStack Packages Compromised to Steal GitHub Secrets
Urgent: 84 TanStack npm packages hijacked to harvest GitHub Actions secrets. Over 12M weekly downloads impacted. Audit your CI/CD pipelines and rotate tokens.
⤷ Title: When Open Source Turns Against You: The TanStack npm Supply Chain Attack Explained
════════════════════════
𐀪 Author: Mluqman150
════════════════════════
ⴵ Time: Tue, 12 May 2026 19:51:25 GMT
════════════════════════
⌗ Tags: #hacking #security #npm #tanstack #malware
════════════════════════
𐀪 Author: Mluqman150
════════════════════════
ⴵ Time: Tue, 12 May 2026 19:51:25 GMT
════════════════════════
⌗ Tags: #hacking #security #npm #tanstack #malware
Medium
When Open Source Turns Against You: The TanStack npm Supply Chain Attack Explained
Modern software development runs on trust.
⤷ Title: Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
Penetration Testing Tools
Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
The Mini Shai-Hulud incursion has once again laid siege to the software supply chain. While the initial offensive
⤷ Title: The npm Supply Chain Attack That Hit TanStack — And the 4-Step Fix That Protects You
════════════════════════
𐀪 Author: Code Coup
════════════════════════
ⴵ Time: Thu, 14 May 2026 23:41:25 GMT
════════════════════════
⌗ Tags: #npm #hacking #npm_package #npm_supply_chain_attack #tanstack
════════════════════════
𐀪 Author: Code Coup
════════════════════════
ⴵ Time: Thu, 14 May 2026 23:41:25 GMT
════════════════════════
⌗ Tags: #npm #hacking #npm_package #npm_supply_chain_attack #tanstack
Medium
The npm Supply Chain Attack That Hit TanStack — And the 4-Step Fix That Protects You
Supply chain attacks on npm are accelerating. TanStack got hit. More will follow.
⤷ Title: OpenAI Forces Code Signing Certificate Rotation After TanStack Supply Chain Breach
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 15 May 2026 04:00:50 +0000
════════════════════════
⌗ Tags: #Data Leak #Atlas Browser #ChatGPT #Code_Signing Certificate #Codex #Cybersecurity 2026 #InfoSec News #macOS security #npm Supply Chain Attack #OpenAI #software update #TanStack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 15 May 2026 04:00:50 +0000
════════════════════════
⌗ Tags: #Data Leak #Atlas Browser #ChatGPT #Code_Signing Certificate #Codex #Cybersecurity 2026 #InfoSec News #macOS security #npm Supply Chain Attack #OpenAI #software update #TanStack
Daily CyberSecurity
OpenAI Forces Code Signing Certificate Rotation After TanStack Supply Chain Breach
OpenAI rotates code signing certificates following the TanStack npm breach. macOS users must update ChatGPT and Codex manually before June 12, 2026.