ended5월 12일· 1 sources

사후 분석: TanStack npm 공급망 침해

Why it matters

This attack highlights a sophisticated evolution in supply chain threats where attackers exploit GitHub Actions features like pull_request_target and OIDC trusted publishing to bypass traditional token-based security. It underscores the critical need for developers to strictly monitor CI/CD permissions and implement robust secrets management to prevent lateral movement and large-scale credential harvesting.

1
Sources
+0
24h
Growth
132d
Active
TanStacksupply chain attackGitHub ActionsOIDCcache poisoningcredential theft

Sources

Related Issues