84 malicious npm versions in 6 minutes: the 2026 TanStack trusted-publishing breach and the CI config that stops it
TanStack's release pipeline authenticated 84 malicious npm versions in six minutes using a valid OIDC token. No token was stolen. Here is the chain, and the controls that close it as of July 2026.