
The TanStack npm attack shows how fragile modern JavaScript supply chains can be
A detailed breakdown of the May 2026 Mini Shai-Hulud attack on TanStack npm packages, how GitHub Actions cache poisoning and OIDC trusted publishing were abused, what the malware tried to steal, and how developers should respond.




















