ended5월 12일· 1 sources

Weaponized Automation: How TanStack's Release Pipeline Was Turned Against Itself

TanStack 공급망 피격: 계정 탈취 없이 무너진 npm 자동화 배포 시스템

Why it matters

This breach demonstrates a sophisticated evolution in supply chain attacks where legitimate CI/CD infrastructures are manipulated into self-publishing malware without stealing developer credentials. It signals a shift toward infrastructure-level exploits, making the security of automated OIDC tokens and GitHub Actions cache a top priority for developers.

1
Sources
+0
24h
Growth
132d
Active
TanStacknpmGitHub ActionsCI/CD securityOIDC tokensupply chain attack

Sources

Related Issues