ended5월 12일· 1 sources
사후 분석: TanStack npm 공급망 침해
Why it matters
This attack highlights a sophisticated evolution in supply chain threats where attackers exploit GitHub Actions features like pull_request_target and OIDC trusted publishing to bypass traditional token-based security. It underscores the critical need for developers to strictly monitor CI/CD permissions and implement robust secrets management to prevent lateral movement and large-scale credential harvesting.
1
Sources
+0
24h
—
Growth
132d
Active
TanStacksupply chain attackGitHub ActionsOIDCcache poisoningcredential theft