GitHub Actions and Pages are degraded due to authentication issues; ongoing investigations with uptime data implying reliability risk for developers.
TanStack disclosed a multi-vector npm supply-chain compromise affecting 84 malicious package versions across 42 @tanstack/* packages, traced to a PR-wrapping cache-poisoning chain and in-memory OIDC token exfiltration, with deprecation and credential-rotation guidance following rapid external detection.
TanStack npm packages were compromised via a supply-chain attack using optionalDependencies to pull in a malicious git commit; payload exfiltrates credentials and republishes vulnerable packages; GitHub Actions OIDC trusted-publisher config suggests CI workflow compromise; multiple TanStack packages affected with two bad versions each, plus broader ecosystem risk.
Open-source, browser-based collaborative Python IDE for education with real-time editing, drawings, and voice chat, backed by a Django/PostgreSQL stack and released as v1.0.0 (48 stars).
Subscribe for real-time topic updates and unlimited access to our intelligence platform.