#tanstack,


CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

Sep 19, 2026 // 14:51

An attacker copied about 170 of CrowdSec’s private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said […]

GitHub links repo breach to TanStack npm supply-chain attack

May 21, 2026 // 10:36

GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS Code extension, compromised in last […]

Grafana breach caused by missed token rotation after TanStack attack

May 20, 2026 // 18:56

The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the TanStack npm supply-chain attack last […]

Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

May 20, 2026 // 13:41

Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised. It […]

TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates

May 15, 2026 // 14:06

OpenAI has disclosed that two of its employee devices in its corporate environment were impacted via the Mini Shai-Hulud supply chain attack on TanStack, but […]

OpenAI confirms security breach in TanStack supply chain attack

May 15, 2026 // 00:17

OpenAI says two employees’ devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company […]

Shai Hulud attack ships signed malicious TanStack, Mistral npm packages

May 12, 2026 // 14:36

Hundreds of packages across npm, PyPI, and Composer have been compromised in a new Shai-Hulud supply-chain campaign delivering credential-stealing malware targeting developers. The attacker hijacked […]

Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages

May 12, 2026 // 11:52

TeamPCP,  the threat actor behind the recent supply chain attack spree, has been linked to the compromise of the npm and PyPI packages from TanStack, […]