Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
…In the long term, to mitigate the risk from similar attacks, consider enforcing lockfile-only installs, which should prevent auto/silent package updates. UPDATE [08:36 EST]: Added information from Microsoft Threat…