ended5월 12일· 1 sources
TanStack Ecosystem Hit by Sophisticated Multi-Stage Supply-Chain Attack
TanStack 뒤흔든 역대급 공급망 공격, GitHub Actions의 ‘신뢰 장벽’이 뚫렸다
Why it matters
This compromise underscores the severe risks of misconfiguring GitHub Actions when handling untrusted fork pull requests. The attack's use of chained vulnerabilities and its self-propagating nature represents a significant escalation in the complexity of modern npm supply-chain threats.
1
Sources
+0
24h
—
Growth
132d
Active
TanStacknpm supply-chainGitHub ActionsOIDC tokenCache poisoning