Decompiled: How a Poisoned TanStack Package Punched Two OpenAI Laptops
Behind the meter on the latest npm supply-chain hit: a malware strain called Mini Shai-Hulud rode legitimate publishing credentials into 84 tainted releases across 42 packages, including @tanstack/react-ro