12:00
2026-05-11
tanstack.com
ai-safety
Postmortem: TanStack npm supply-chain compromise
On May 11, 2026, an attacker compromised the TanStack Router/Start repository and published 84 malicious npm package versions across 42 packages by exploiting a pull_request_target vulnerability, GitHβ¦