Devops iconDevopsSep 24, 2026

Why Software Supply Chain Security Is Moving to the Gate

May 2026: attackers forge valid provenance for 42 TanStack packages on npm, with 84 malicious versions shipped before detection. August 2026: a worm uses one maintainer's stolen credentials to self-propagate through keyv and its dependent packages.

Why Software Supply Chain Security Is Moving to the Gate

Share this story

Send the public story page.

Useful takeaways from this story.

May 2026: attackers forge valid provenance for 42 TanStack packages on npm, with 84 malicious versions shipped before detection.

August 2026: a worm uses one maintainer's stolen credentials to self-propagate through keyv and its dependent packages.

March 2026: malicious versions of axios get published directly to npm.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

May 2026: attackers forge valid provenance for 42 TanStack packages on npm, with 84 malicious versions shipped before detection. August 2026: a worm uses one maintainer's stolen credentials to self-propagate through keyv and its dependent packages. March 2026: malicious versions of axios get published directly to npm.

Example or evidence

  • March 2026: malicious versions of axios get published directly to npm.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app