Supply Chain Attacks Aren't Just a Big Library Problem — Here's What You Can Do Today (opens in new tab)
In May 2026, a worm called Shai-Hulud compromised 42 TanStack packages — including @tanstack/react-router, a library sitting in millions of JavaScript projects. It was live for about 3 hours. That was enough. If you installed dependencies that day, you may have been affected without knowing it. This post isn't for the people who maintain those libraries. It's for the rest of us — the developers who just use them. "Fun fact" 1 It was live ~3 hours. @tanstack/react-router alone gets 12.7 millio...
Read the original article