Update 5:05 PT: The attack has now expanded well beyond @TanStack and @Mistral.
373 malicious package-version entries across 169 npm package names, including @uipath, @squawk, @tallyui, @beproduct, and more.
The malware propagates by stealing your CI credentials and using them to publish new compromised versions.
Full IOCs, affected package list, and detection steps: https://t.co/jWG9DUCu3x
@elonmusk I was back in 2019 promised on a vision of a cybertruck, where I eagerly paid a reservation fee for. Till today product still on the Belgian website with no clear forecast on delivery. Hate it. Would not recommend.
Bij https://t.co/2vfwCzKiWw zoeken we enthousiaste werkkrachten om de beste guacamole ter wereld te maken en die snel en kwaliteitsvol bij onze klanten te krijgen. Ken je iemand, wil je zelf erbij zijn, heb je goesting in een productie-omgeving, DM me. #productie#operator