Postmortem: TanStack npm supply-chain compromise
↗TanStack disclosed a multi-vector npm supply-chain compromise affecting 84 malicious package versions across 42 @tanstack/* packages, traced to a PR-wrapping cache-poisoning chain and in-memory OIDC token exfiltration, with deprecation and credential-rotation guidance following rapid external detection.
May 12, 20261%