TanStack npm Supply Chain Attack: How Cache Poisoning Compromised 42 Packages in 6 Minutes
On May 11, 2026, an attacker published 84 malicious versions across 42 @tanstack/* packages by chaining pull_request_target abuse, GitHub Actions cache poisoning, and OIDC token extraction from runner memory. Part of the Mini Shai-Hulud campaign that hit 170+ packages across npm and PyPI.




































