GitHub Actions security

TanStack npm Supply Chain Compromise: 84 Malicious Versions Detected Across 42 Packages
An attacker exploited three chained vulnerabilities to publish 84 malicious npm versions across 42 TanStack packages on May 11. Detection occurred within 20 minutes; all versions were deprecated and npm security was engaged.

Shai-Hulud npm Worm Targets TanStack Ecosystem With Destructive Payload
A new Shai-Hulud npm worm variant targeted 42 TanStack packages with a payload that steals credentials and threatens to wipe user home directories if stolen tokens are revoked.
