🏷️Topic

Socket.dev

2 articles
First tracked: Apr 3, 2026
Last updated: May 12, 2026

Latest Coverage

TanStack NPM Packages Compromised

↗

TanStack npm packages were compromised via a supply-chain attack using optionalDependencies to pull in a malicious git commit; payload exfiltrates credentials and republishes vulnerable packages; GitHub Actions OIDC trusted-publisher config suggests CI workflow compromise; multiple TanStack packages affected with two bad versions each, plus broader ecosystem risk.

May 12, 20261%

Post Mortem: axios NPM supply chain compromise

↗

Two malicious Axios releases were briefly published on npm due to a compromised maintainer account, introducing a remote-access trojan via plain-crypto-js; remediation focuses on OIDC-based publishing, immutable releases, CI publishing, and credential hygiene.

Apr 3, 20261%

Related Entities

🏷️TopicStepsecurity
4
👤PersonOpenjs Security Working Group
1
🏷️TopicNpm
14
📈StockOIDC
4
🏷️TopicSupply_chain_attack
3