Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
…Application security company StepSecurity notes that the threat actor published the infected packages via the legitimate CI/CD pipeline, carrying valid SLSA provenance attestations issued by npm's signing infrastructure and "tied…