A supply-chain attack against the widely used TanStack JavaScript packages planted malware that not only steals developer credentials but detonates a destructive "dead man's switch"—wiping files and locking out users the moment defenders try to revoke the stolen access. The incident, disclosed on May 11, 2026, shows how attackers are now weaponizing the standard security playbook itself, and how the credential-rich environments around AI-assisted coding tools have become an attractive target.
Continue reading
The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in✓ Signed in — this article isn’t included in your current plan.