Blogs

TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack

Socket

Socket detected 84 compromised TanStack npm package artifacts modified with suspected CI credential-stealing malware.

Visit Site

Blogs Socket

BlogsPopular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain AttackSocket BlogsOpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain AttackSocket BlogsSupply Chain Attack on Axios Pulls Malicious Dependency from npmSocket BlogsRe-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-HuludSocket BlogsHow to Protect Your Projects from the Risks of Deprecated npm PackagesSocket BlogsSuno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Music ScrapingSocket BlogsWebinar Recap: Webinar Recap: Securing the Software Supply Chain with Docker BusinessDocker BlogsProtecting Secrets with DockerDocker ResourcesNEXTJS_MISSING_MODULARIZE_IMPORTSVercel BlogsChatGPT: Putting the “AI” in “Plagiarism” worldwide?Deepgram BlogsLarge-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation CampaignSocket NewsWhen "Everything" Becomes Too Much: The npm Package Chaos of 2024Socket BlogsPolinRider Spreads Through Compromised GitHub Accounts and PackagistSocket BlogsSecuring the Financial Frontier: How Capital One Uses Socket for Open Source SecuritySocket BlogsCleaning up import paths in JS/TS packagesSocket BlogsSigning is Just the StartSocket ResourcesHow do I use the latest npm version for my Vercel Deployment?Vercel BlogsHow RHI Magnesita is creating AI video 40% faster and achieves 3x engagementSynthesia BlogsIntroducing Socket Firewall: Free, Proactive Protection for Your Software Supply ChainSocket BlogsNew Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMsSocket