Skip to content
AppSec Santa Weekly

#9 โ€” Your Supply Chain's Provenance Just Lied To You

On May 11, 2026, TanStack's npm packages shipped malicious code from a trusted publishing pipeline. Provenance attests pipeline identity, not pipeline honesty.

| 61 releases 5 min read

Want this in your inbox?

Every Tuesday, no spam.

Subscribe