Earlier May 11th, many TanStack Router/Start packages were compromised, but quickly mitigated. Here is a full post mortem on the incident: tanstack.com/blog/npm-sup...
Postmortem: TanStack npm supply-chain compromise | TanStack Blog
On 2026-05-11, an attacker chained a pull_request_target Pwn Request, GitHub Actions cache poisoning across the fork↔base trust boundary, and OIDC token extraction from runner memory to publish 84 mal...
tanstack.com