A Popular Open-Source Library Just Got Hacked Through a GitHub Pull Request. Here's What Actually Happened - and What to Do.
Yesterday, 42 npm packages from the widely-used TanStack library were briefly replaced with malware that steals AWS credentials, SSH keys, and GitHub tokens. The attack exploited a trusted open-source workflow. If anyone on your team ran npm install on May 11th, you need to read this today.
May 12, 2026 · By DANNY KOWALSKI