Popular TanStack NPM packages were compromised, affecting developers who use the widely-adopted routing and utility libraries. The vulnerability was reported on the TanStack Router GitHub issue tracker.
TanStack, known for maintaining several high-profile NPM packages including Router and Query, experienced a security breach affecting its package distribution. The compromise was disclosed through GitHub issue #7383 on the TanStack Router repository.
The incident generated significant attention in the developer community, with the GitHub issue receiving 236 upvotes and 62 comments on Hacker News, indicating widespread concern among affected users.
Details regarding the scope of the compromise, specific packages impacted, and remediation steps remain under investigation. Developers using TanStack packages should monitor official channels for security advisories and guidance on verifying package integrity.
No statement has yet been released on the attack vector or whether malicious code was injected into live packages. Users are advised to check their dependency versions and security scanning tools for potential indicators of compromise.
More than 50 ads containing AI-generated child sexual abuse material appeared on Facebook, Instagram, Messenger, and Threads, with some running as recently as this week, according to Meta's ad library data.
AI-generated phishing infrastructure is evolving faster than blocklists can track, rendering domain-based security strategies obsolete. Browser-level detection focused on attack techniques offers a more effective defense.
Google Blogger has locked and deleted hundreds of blogs following a false positive that incorrectly flagged them for malware violations. The error affected sites across the platform without warning.
A vulnerability in WebKit allows IP addresses and DNS queries to bypass proxy browsers and Apple's iCloud Private Relay, undermining privacy protections for users relying on these services.