A self-replicating worm has been integrated into 42 TanStack NPM packages
As a result of the compromise of the release process based on GitHub Actions, attackers were able to publish 84 malicious versions covering 42 NPM packages from the TanStack stack in the NPM repository. Some of the compromised packages had over 10 million downloads per week. Access to publishing releases was gained due to an incorrect configuration of pull_request_target 'Pwn Request' in GitHub Actions (indicating […]
