We are actively investigating this security incident and sharing our findings here: www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem
We are actively investigating this security incident and sharing our findings here: www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem
Thanks for being patient with us, we really appreciate it.
We've published our postmortem on tanstack.com/blog/npm-supply-chain-compromise-postmortem. It contains all the information we've uncovered so far, along with a timeline of the attack.