Skip to content
TanStack Considers Invitation-Only Pull Requests After Supply Chain Attack

TanStack Considers Invitation-Only Pull Requests After Supply Chain Attack

First seen 19 May 2026, 15:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 20, 2026 at 14:44 UTC

The TanStack team is evaluating security measures following a supply chain attack that exploited a GitHub Actions misconfiguration. The Shai-Hulud worm, used by TeamPCP, triggered a pull request that executed malicious code, poisoning a shared cache across the repository. In response, TanStack has removed the vulnerable pull_request_target feature from its CI pipeline and implemented several security enhancements, including disabling caches and pinning actions to commit SHA hashes. A drastic proposal under consideration is making pull requests by invitation only, a significant shift from the open-source model. While this could enhance security, it may deter contributions from the community. The team emphasizes that they will not transition to a closed-source model but may require discussions before PR submissions. The incident highlights broader concerns regarding supply chain security and GitHub's role in cache management.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 124d ago How this analysis works

Timeline

2026-05-12
Supply chain attack occurred
The Shai-Hulud worm exploited a GitHub Actions misconfiguration, impacting TanStack's repository.
The Register
2026-05-18
TanStack announces security measures
The team outlined steps taken post-attack, including removing vulnerable features and enhancing security protocols.
The Register
2026-05-19
Discussion on invitation-only PRs
TanStack is considering making pull requests by invitation only to prevent future attacks, while maintaining an open-source ethos.
Devclass

More articles in this cluster (2)

Following this threat?

Track Shai-Hulud Worm and TanStack in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed