Why Software Supply Chain Security Is Moving to the Gate
May 2026: attackers forge valid provenance for 42 TanStack packages on npm, with 84 malicious versions shipped before detection. August 2026: a worm uses one maintainer's stolen credentials to self-propagate through keyv and its dependent packages.
