Mini Apps Carnival is now live on @StartaleApp.
One hub. 17 Mini Apps. One quest per app. Multiple reward layers.
If you've been waiting for a reason to explore Mini Apps, this is it 👇
1/ The Mini Apps Carnival is in Soneium town, powered by @StartaleApp. 🎡
17 mini apps. One ecosystem. Double rewards on most of the quest.
If you play games this is your moment. 🎮🧵
SECURITY ADVISORY — TanStack npm packages
A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package.
Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down.
Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys.
If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised:
• Rotate cloud, GitHub, and SSH credentials immediately
• Audit cloud audit logs for the last several hours
• Pin to a prior known-good version and reinstall from a clean lockfile
Detection — the malicious manifest contains:
"optionalDependencies": {
"@tanstack/setup": "github:tanstack/router#79ac49ee..."
}
Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root).
Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level.
Full technical breakdown, complete package and version list, and rolling status updates:
https://t.co/Zy8qG7PA9f
Credit to the security researcher for responsible disclosure.
The momentum continues ↔️
3 new Mini Apps just landed on the Startale App, bringing even more onchain experiences to the @soneium ecosystem.
Meet the new arrivals 👇🏻
⚠️ Multiple Critical Vulnerabilities Patched in Next.js and React Server Components
Source: https://t.co/yzX2k5M1hk
Next.js addresses a dozen vulnerabilities, including denial-of-service, middleware bypass, server-side request forgery, and cross-site scripting.
The flaws affect Next.js versions 13.x through 16.x using the App Router, as well as React Server Components packages for versions 19.x.
A high-severity denial-of-service vulnerability tracked as CVE-2026-23870 affects React Server Components packages for versions 19.x and all Next.js App Router deployments on versions 13.x, 14.x, 15.x, and 16.x.
Organizations running affected Next.js versions should prioritize upgrading immediately.
#cybersecuritynews #Vulnerability
We're looking for 100 SuperVerse legends. Got what it takes?
$10 in $SUPER rewards each
✅ Sign up via the link below
👋🏻 Complete 1 GM
🔁 RT this tweet and follow @StartaleGroup and @SuperVerse
https://t.co/RmI9NzmHfI
Sweet & Simple ⭐️
Startale accelerates its growth in Abu Dhabi by joining @hub71ad Programme, an initiative by the Abu Dhabi Department of Economic Development, @AbuDhabiDED, powered by @Mubadala and based in Abu Dhabi Global Market, @ADGlobalMarket.
Under a comprehensive, internationally-recognized regulatory framework, this unlocks global scale for @Soneium, Strium, @StartaleApp, and our stablecoin initiatives (Startale USD and @JPYStableCoin stablecoin).
Learn more about our expansion👇
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly.
A Vercel employee got compromised via the breach of an AI platform customer called https://t.co/7PY6gGtzgI that he was using. The details are being fully investigated.
Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments.
Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration.
We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel.
At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community.
The recommendation for all Vercel customers is to follow the Security Bulletin closely (https://t.co/BLVnic9fJC). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature.
In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback.
We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance.
It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
Finally, @Tan_Stack Start now supports React Server Components!
Start's RSCs are a truly fetchable, cacheable and composable primitive that work with your favorite tools instead of dictating your entire architecture.
Oh, and one more thing... "Composite Components" 😉
🔗⬇️🧵