logo

TanStack weighs invitation-only pull requests after supply chain attack

ID: fc1b32dc-1d82-522f-90ac-3238c63818c8

STIX ID: report--fc1b32dc-1d82-522f-90ac-3238c63818c8

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

...
...

A malicious pull request exploited TanStack's use of GitHub Actions' pull_request_target to run the Shai-Hulud worm (attributed to TeamPCP), which poisoned a repository-wide cache and can extract secrets from CI memory; TanStack has removed pull_request_target, disabled caches, pinned actions to SHAs, changed 2FA methods, and is considering invitation-only PRs to prevent future supply-chain abuses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.