Security researchers uncovered a supply chain attack where a fake TanStack npm package used automated postinstall scripts to harvest environment…