supply-chain
GitHub links repo breach to TanStack npm supply-chain attack
High
Summary
A supply-chain attack targeting GitHub originated with a malicious version of the Nx Console VS Code extension, facilitated by the TeamPCP threat group. The attack compromised over 3,800 internal repositories and extended to other projects including TanStack, Mistral AI, UiPath, Guardrails AI, and OpenSearch, leveraging stolen CI/CD credentials. GitHub is actively investigating and mitigating the damage, rotating critical secrets and monitoring for further activity.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data