This attack passed all checks designed to stop it. Farida Khalaf shares a practical system for catching it the biggest security mistake AI-assisted builders make after deployment.
On May 11, 2026. 19:20 UTC, something changed inside the TanStack project on GitHub. Theoretically, nothing broke. No warning lights flashed.
And yet.
During the 6 minutes that followed, one of the most sophisticated open-source supply chain attacks ever documented fooled even seasoned builders. 84 malicious versions appeared across 42 npm packages in the TanStack ecosystem.
The packages, trusted by many, checked every box. They had valid SLSA Build L3 provenance (their origin could be traced) and passed most standard integrity checks. By every measure builders normally use to separate legitimate files from suspicious ones, they looked legitimate.
Top comments (0)