Hackers hijacked 42 npm packages in six minutes by poisoning GitHub Actions pipelines

May 19, 2026 InfoQ global 796 words

TL;DR

On May 11 between 19:20 and 19:26 UTC, attackers compromised 42 TanStack npm packages and published 84 malicious versions by exploiting GitHub Actions cache poisoning and unsafe workflow permissions without ever stealing npm credentials directly.

The malware, which ran automatically on package installation, harvested cloud credentials from AWS, GCP, Kubernetes, GitHub, SSH keys, and npm configs from developer machines and CI environments, then attempted to self-propagate to other packages maintained by affected developers.

External security researchers detected the breach within roughly 20 minutes; TanStack has since removed unsafe workflow patterns, pinned GitHub Actions to immutable SHAs, purged caches, added stricter publishing controls, and acknowledged that it learned of the attack from outside researchers, not its own monitoring.

Intelligence

For developers and engineering teams building on open source tooling, particularly those using GitHub Actions for automated deployments, this attack confirms that CI/CD pipelines are now a primary target, not an afterthought.

Any team running pull_request_target workflows or relying on shared GitHub Actions caches without strict isolation should audit those configurations in the next 30 days, as the attack pattern used here requires no stolen passwords and leaves few obvious traces.

Over the next 6–12 months, enterprises and funded startups in Lagos and across Africa that are scaling engineering teams and adopting cloud-native infrastructure will face growing exposure to supply-chain attacks as their dependency footprints expand.

5 companies and people in this story have tracked profiles.

Recommended reading

Picked for you by topic, popularity and relevance — not just the newest posts.

Related topics

South Africa's financial regulator bars three Africa Bitcoin Corporation executives from the financial services industry for 20 years.

REGULATION | South African Financial Regulator Bars Africa Bitcoin Corp CEO and Executives for 20 Years

Related topics

Nigeria's Federal Ministry of Education has fully automated the academic certificate verification and evaluation process online.

FG automates academic certificate verification, authentication process

Related topics

Mastercard partners with Busha to launch its secure crypto transfer service, Mastercard Crypto Credential, in Nigeria.

Mastercard partners with Busha to bring trusted and simpler digital asset transfers to Nigeria

Related topics

Google and Kickstarter launch applications for the Next Wave Fund, offering African tech startups $10,000 and crowdfunding support.

African startups invited to apply for Kickstarter, Google Next Wave Fund

Related topics

Egypt partners with Intel to train one million citizens annually in artificial intelligence over the next three years.

Egypt, Intel partner to train 1 million citizens annually in AI