Filters
1158
456
234
167
156
78
43
38
37
35
33
28
28
26
23
22
21
19
19
16
16
16
16
12
11
11
11
11
11
10
10
9
8
7
7
6
6
6
6
5
5
5
5
5
4
4
4
4
3
3
3
3
3
3
3
3
3
3
3
3
3
2
2
2
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
0
0
0
0
602
575
395
391
315
304
189
128
127
125
122
120
97
82
77
69
57
48
10
1
1
1
Article

Hackers hijacked 42 npm packages in six minutes by poisoning GitHub Actions pipelines

InfoQ May 19, 2026

TL;DR

On May 11 between 19:20 and 19:26 UTC, attackers compromised 42 TanStack npm packages and published 84 malicious versions by exploiting GitHub Actions cache poisoning and unsafe workflow permissions without ever stealing npm credentials directly.

The malware, which ran automatically on package installation, harvested cloud credentials from AWS, GCP, Kubernetes, GitHub, SSH keys, and npm configs from developer machines and CI environments, then attempted to self-propagate to other packages maintained by affected developers.

External security researchers detected the breach within roughly 20 minutes; TanStack has since removed unsafe workflow patterns, pinned GitHub Actions to immutable SHAs, purged caches, added stricter publishing controls, and acknowledged that it learned of the attack from outside researchers, not its own monitoring.

Intelligence

For developers and engineering teams building on open source tooling, particularly those using GitHub Actions for automated deployments, this attack confirms that CI/CD pipelines are now a primary target, not an afterthought.

Any team running pull_request_target workflows or relying on shared GitHub Actions caches without strict isolation should audit those configurations in the next 30 days, as the attack pattern used here requires no stolen passwords and leaves few obvious traces.

Over the next 6–12 months, enterprises and funded startups in Lagos and across Africa that are scaling engineering teams and adopting cloud-native infrastructure will face growing exposure to supply-chain attacks as their dependency footprints expand.

Funding extracted from this article

0

No funding rounds were extracted from this article.

Regulatory activity extracted

0

No regulatory actions were extracted from this article.

Tenders extracted

0

No tenders were extracted from this article.

Further reading

More on the companies named in this article.

Companies named

4

People named

0

No people were extracted from this article.

Elsewhere on these companies

Other recorded activity involving the same companies.