TanStack npm supply-chain attack: how a Dependabot bump spread a worm

DEV Community·0 points·axrisi·about 3 hours ago·dev.to

TanStack npm supply-chain attack, step by step: a poisoned CI cache, 84 bad versions, then a Dependabot bump that republished 22 packages in 95 minutes.

Read the full article at dev.to →

Related stories

Related topics