ended5월 12일· 1 sources
Weaponized Automation: How TanStack's Release Pipeline Was Turned Against Itself
TanStack 공급망 피격: 계정 탈취 없이 무너진 npm 자동화 배포 시스템
Why it matters
This breach demonstrates a sophisticated evolution in supply chain attacks where legitimate CI/CD infrastructures are manipulated into self-publishing malware without stealing developer credentials. It signals a shift toward infrastructure-level exploits, making the security of automated OIDC tokens and GitHub Actions cache a top priority for developers.
1
Sources
+0
24h
—
Growth
132d
Active
TanStacknpmGitHub ActionsCI/CD securityOIDC tokensupply chain attack