TanStack npm supply-chain attack: how a Dependabot bump spread a worm
DEV Community·0 points·axrisi·about 3 hours ago·dev.to
TanStack npm supply-chain attack, step by step: a poisoned CI cache, 84 bad versions, then a Dependabot bump that republished 22 packages in 95 minutes.
Read the full article at dev.to →
Related stories
- Ars Technica · 0 points · 11 days ago
- Hacker News · 6 points · 11 days ago
- Lobsters · 5 points · about 2 months ago
- Anthropic is a supply chain risk for all of usbuilding138.comHacker News · 1 points · 3 days ago
- Tracing the Supply Chain Attack on Androidkrebsonsecurity.comLobsters · 3 points · over 7 years ago
- Hacker News · 2 points · 10 days ago