The npm packages @tanstack/history (1.161.9, 1.161.12) and more than 50 other packages across the @tanstack, @mistralai, @uipath, @squawk, and safe-action namespaces have been compromised and use a classic drop-and-execute attack pattern to run an infostealer that harvests GitHub credentials and cloud secrets. The attack patterns are similar to past Shai-Hulud compromises and the recent intercom-client@7.0.4 […]