Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

How a Misconfigured CI Workflow Became an npm Supply-Chain Compromise

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Robert Haynes
Word Count
2,512
Company Posts That Month
25
Language
English
Hacker News Points
-
Post removed?
No
Summary

In May 2026, a sophisticated supply-chain attack was executed on the npm registry, targeting 42 @tanstack/* packages through 84 malicious versions, despite the presence of rigorous security measures such as two-factor authentication and OIDC trusted publishing. The attack exploited overlooked vulnerabilities in GitHub Actions, specifically using the "Pwn Request" pattern to run fork-controlled code in a trusted context, cache poisoning across trust boundaries, and extracting OIDC tokens from runner memory. This allowed the attacker to publish malicious packages without stealing credentials or bypassing established security controls. The attack chain involved PR-time cache poisoning, erasing evidence, leveraging legitimate pushes to main, and stealing tokens for unauthorized publishing, all while maintaining the appearance of legitimate operations. The incident highlights the challenges of defending against attacks that exploit legitimate workflow behaviors and emphasizes the need for stronger isolation boundaries and more granular trust models in CI/CD systems to prevent similar compromises in the future.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 3 2,152 360 101 +18%
Kubernetes 1 1,965 371 106 -15%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.