Реклама партнера — Название партнёра
UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉

TanStack was hit by an attack by attackers. Infected versions went straight to the npm registry. What are the consequences and what to do

Unknown attackers carried out an attack on TanStack: chains of vulnerabilities in the GitHub Actions architecture were exploited, and infected versions were published directly to the npm registry.

Leave a comment
TanStack was hit by an attack by attackers. Infected versions went straight to the npm registry. What are the consequences and what to do

Unknown attackers carried out an attack on TanStack: chains of vulnerabilities in the GitHub Actions architecture were exploited, and infected versions were published directly to the npm registry.

According to DOU, the attackers compromised 42 ecosystem packages at once, releasing 84 malicious versions.

The attack reportedly occurred by bypassing standard security mechanisms, and the hackers created a disguised fork of the TanStack/router repository and sent a PR.

«Due to the use of a vulnerable pull_request_target trigger in the bundle-size.yml configuration file, the malicious code was automatically executed on GitHub servers without any manual approval from maintainers,» the material states.

The stolen data was leaked via the file upload network of the decentralized messenger Session (domains filev2.getsession.org and seed.getsession.org).

At the same time, thanks to end-to-end encryption and the lack of a single command server, it is almost impossible to block this traffic using classic methods by IP.

Anyone who installed any packages from the @tanstack/* family yesterday is advised to check, but the query, table, form, virtual, and store packages remained clean.

As dev.ua recently reported, the popular JavaScript library Axios, which is used in thousands of projects, was compromised through a supply chain attack .

Hackers attack Cisco: 3 million Salesforce records and GitHub repositories allegedly stolen
Hackers attack Cisco: 3 million Salesforce records and GitHub repositories allegedly stolen
On the topic
Hackers attack Cisco: 3 million Salesforce records and GitHub repositories allegedly stolen
Google spoke about the Coruna exploit kit with which Russian hackers attacked Ukrainian iOS users
Google spoke about the Coruna exploit kit, which Russian hackers used to attack Ukrainian iOS users
On the topic
Google spoke about the Coruna exploit kit, which Russian hackers used to attack Ukrainian iOS users
Read the country's main IT news in our Telegram
Read the country’s main IT news in our Telegram
On the topic
Read the country’s main IT news in our Telegram

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.