Your next supply-chain attack will come from a package you've never heard of
4d ago · 3 min read · Most developers think supply-chain attacks happen to other people. Then TanStack happened. Last week, a popular npm package in the TanStack ecosystem was compromised. Attackers pushed a malicious version that exfiltrated environment variables from an...
Join discussion