The TanStack Attack Did Not Steal a Maintainer Token. It Stole the Process Minting One.
technical
7 min read

The TanStack Attack Did Not Steal a Maintainer Token. It Stole the Process Minting One.

TanStack's May 2026 npm compromise hijacked a GitHub Actions runner via cache poisoning and OIDC memory extraction. SLSA Build Level 3 provenance attested it as valid.

Harper Foley

Harper Foley

General Manager at Tribe AI. Former Navy EOD.

Share