info@news-matic.com

details

Malicious TanStack Package Abuses Postinstall Script to Steal Developer Secrets

A malicious npm package named “tanstack” has been discovered deploying a stealthy data exfiltration campaign, targeting developers through a deceptive naming strategy. A malicious npm package named “tanstack” has been discovered deploying a stealthy data exfiltration campaign, targeting developers through a deceptive naming strategy and a hidden postinstall script. The package, impersonating the well-known TanStack... [3557 chars]

Cookie Consent + Tracking