Cache-poisoning caper turns TanStack npm packages toxic

https://image.theregister.com/257723.jpg?imageId=257723&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Six-minute supply chain blitz pushed 84 malicious versions with credential theft and disk-wiping code

An attacker has published 84 malicious versions of official TanStack npm packages, with the impact includingcredential theft, self-propagation, and complete disk wipe of an infected host.

The attack is part of a wave of attacks across npm and PyPI,continuing the Mini Shai-Hulud campaign. Supply chain security company Socket reports that other compromised packages include the OpenSearch client, Mistral AI, UiPath, andGuardrails AI.

Malicious npm packages for TanStack, an open sourceapplication stack, were publishedbetween 19:20 and 19:26 UTC on May 11. The attack was detected andreported within 30 minutes by StepSecurity, triggering incident response and npm deprecation. GitHub published a security advisory at 21:30 UTC, including a list of affected packages.

TanStack founder Tanner Linsley published a postmortemdescribing how the attacker used a malicious commit on a fork to create a pullrequest on the...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE