TanStack Is Attacked Again
Viking(@vikingmute)501 字 (约 3 分钟)
87
Attackers used a fake PR to inject malicious code, pollute pnpm cache, and auto-publish 84 compromised npm versions within minutes, affecting 42 packages.
入选理由:攻击者利用伪造的 zblgg 用户提交 PR 7378,成功绕过审查
FeaturedTweet#npm#supply-chain attack#GitHub Actions#TanStack#security中文
