A fake “tanstack” npm package published four malicious versions in 27 minutes today, exfiltrating .env files via a postinstall hook. Here’s what happened, who was affected, and how to rotate your credentials. Category: Vulnerabilities & Threats
Need help?
Contact usA fake “tanstack” npm package published four malicious versions in 27 minutes today, exfiltrating .env files via a postinstall hook. Here’s what happened, who was affected, and how to rotate your credentials. Category: Vulnerabilities & Threats