WhisperX tag archive

#tanstack

This page collects WhisperX intelligence signals tagged #tanstack. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (7)

The Lab · 2026-05-12 03:18:21 · Techmeme Echo RSS

1. Supply Chain Compromise Targets TanStack npm Ecosystem; Mini Shai-Hulud Attack Expands to Mistral Packages

A coordinated supply chain attack dubbed "Mini Shai-Hulud" has successfully infiltrated the npm registry, compromising multiple packages associated with TanStack, a widely-used suite of web development tools. Security researchers at Socket have identified the breach and are urging developers to immediately audit their ...

The Lab · 2026-05-12 04:48:18 · Hacker News

2. npm Supply Chain Attack Exposes 170+ Packages Including TanStack and Mistral AI—Maintainer Accounts Left Uncompromised

A sweeping npm supply chain attack has surfaced, targeting more than 170 packages with over 400 malicious versions published. The campaign stands out for a critical anomaly: investigators found no evidence that any maintainer accounts were compromised, raising sharp questions about how the malicious code entered the ec...

The Lab · 2026-05-12 16:48:26 · Mastodon:hachyderm.io:#infosec

3. TanStack and 160+ npm/PyPI Packages Hit in Self-Spreading Supply Chain Worm Attack

A sophisticated supply chain attack has compromised TanStack and over 160 packages across the npm and PyPI ecosystems, security researchers at Orca Security report. The attack, characterized as a self-propagating worm, represents a significant escalation in software supply chain threats, targeting widely-used developer...

The Lab · 2026-05-12 21:18:23 · Mastodon:mastodon.social:#infosec

4. Threat Actor 'mini-shai-hulud' Compromises Multiple Tanstack NPM Packages in Supply Chain Attack

Security researchers at Wiz.io have identified a new wave of supply chain attacks targeting the Tanstack ecosystem, with the threat actor tracked as "mini-shai-hulud" injecting malicious code into multiple NPM packages. The attack follows a pattern consistent with sophisticated open-source supply chain intrusions, wher...

The Lab · 2026-05-13 00:18:27 · CyberScoop RSS

5. Mini Shai-Hulud Malware Infiltrates Hundreds of Open-Source Packages, Including TanStack React Router

A sprawling supply-chain attack has embedded credential-stealing malware into hundreds of open-source software packages distributed through major registries, security researchers warned. The campaign, dubbed "mini Shai-Hulud," targets development tools with massive user bases, placing malicious code within reach of dev...

The Lab · 2026-05-14 17:48:23 · Techmeme Echo RSS

6. OpenAI Confirms Supply Chain Breach: Two Employee Devices Hit via TanStack Attack

OpenAI has confirmed that two employee devices were compromised through a supply chain attack targeting TanStack, an open-source software library. The company stated that no user data or production systems were affected by the incident. The breach is part of a broader campaign in which hackers hijacked multiple open-so...

The Lab · 2026-05-14 23:48:33 · Browser The Record

7. OpenAI Forces macOS Update After TanStack Supply Chain Attack Compromised Signing Keys

OpenAI is requiring all macOS users to update their applications by June 12 or risk losing access to updates and support, after a supply chain attack corrupted the signing keys used to verify the legitimacy of the company's software. The move comes as security researchers track an expanding campaign that compromised Ta...