news.mlab.sh
Back to the feed
supply-chain

GitHub links repo breach to TanStack npm supply-chain attack

High
Summary

A supply-chain attack targeting GitHub originated with a malicious version of the Nx Console VS Code extension, facilitated by the TeamPCP threat group. The attack compromised over 3,800 internal repositories and extended to other projects including TanStack, Mistral AI, UiPath, Guardrails AI, and OpenSearch, leveraging stolen CI/CD credentials. GitHub is actively investigating and mitigating the damage, rotating critical secrets and monitoring for further activity.

Read the full article at BleepingComputer

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.