Get the latest tech news

Postmortem: TanStack NPM supply-chain compromise


On 2026-05-11, an attacker chained a pull_request_target Pwn Request, GitHub Actions cache poisoning across the fork↔base trust boundary, and OIDC token extraction from runner memory to publish 84 malicious versions across 42 @tanstack/* packages on npm. Full postmortem.

None

Get the Android app

Or read this on Hacker News

Read more on:

Photo of postmortem

postmortem

Photo of TanStack

TanStack

Photo of chain compromise

chain compromise

Related news:

News photo

TanStack Start Now Support React Server Components

News photo

React survey shows TanStack gains, doubts over server components

News photo

Postmortem: Our first VLEO satellite mission (with imagery and flight data)