CVE-2026-45321: how attackers hijacked a trusted GitHub Actions publisher to weaponize the npm supply chain
Breakdown of CVE-2026-45321, the TanStack supply chain compromise. An attacker chained a pull_request_target misconfiguration, GitHub Action...