The Pipeline Is the Package: SLSA Provenance Failed Its First Real Test episode artwork

EPISODE · May 13, 2026 · 24 MIN

The Pipeline Is the Package: SLSA Provenance Failed Its First Real Test

from Deep Dive · host Deep Dive

May 11, 2026. Between 19:20 and 19:26 UTC. Six minutes. An attacker published 84 malicious versions across 42 TanStack packages on npm — including React Router with 12.7 million weekly downloads. Every malicious version was signed with valid SLSA build provenance. Every check npm performs passed. The build pipeline that produced the malicious artifacts was the real TanStack pipeline. The attestation wasn't lying.This episode walks the six minutes, what SLSA was supposed to prevent versus what it actually prevents, the six-year arc from SolarWinds Orion to TanStack, and the AI cyber trilogy of the last twelve weeks that makes this the wrong moment for any of it to fail.The attack chain minute by minute. Pwn Request via pull request target. Cache poisoning across the workflow boundary. OIDC token theft from the GitHub Actions runner. Eighty-four npm publishes in sixty seconds, every one producing valid SLSA provenance — because the publishes really came from the official TanStack workflow on the main branch on a hardened build platform. SLSA L3 verified everything it was designed to verify. It just doesn't verify that the inputs to the build script were the intended inputs.Then the lineage. SolarWinds. Codecov. node-ipc. xz utils Jia Tan caught by a Microsoft engineer who noticed half a second of SSH latency. tj-actions. Shai-Hulud. Each moved the trust failure up the stack.And the AI cyber trilogy. Hagendorff in Nature: LRMs jailbreaking LRMs at 97 percent ASR. UK AISI on GPT-5.5 at 71.4 percent expert cyber tasks. Google Threat Intelligence Group confirming the first criminal AI-built zero-day on the same day TanStack got hit. Frontier cyber offense doubling every 3.4 months.Defense in six layers: SLSA provenance, Sigstore, SBOMs, OIDC trusted publishing across npm/PyPI/RubyGems/crates.io, pre-publish package analysis (the layer that actually caught TanStack), runtime detection. What an engineer can do this week: audit pull-request-target workflows, pin third-party actions to commit SHAs, namespace caches by workflow.Plus regulation (U.S. weaker after EO 14306, EU stronger via the Cyber Resilience Act), the maintainer economics problem nobody is fixing, and five predictions.The thesis: the frameworks help. What actually catches the next one is somebody paying attention to a five-times tarball-size anomaly.RELATED EPISODESThe Palo Alto CVE Cluster — sister cyber episode; Klarich's 3-to-5-month window quoted on the recordThe ShinyHunters SSO Breach — SaaS-side attack surface as the trust chain shifted from packages to pipelinesClaude Mythos — the model class behind Google TIG's first criminal AI-built zero-day on May 11The AI Layoff Gap — cybersecurity tributary; security-analyst postings -25.88% as the canary cohortCHAPTERS00:00 Cold open — the 6-minute TanStack window00:47 Show intro and roadmap01:18 Callback — LiteLLM, the same pattern weeks earlier01:58 The attack chain, minute by minute05:56 SLSA — what it actually guarantees08:12 The 6-year lineage — SolarWinds to TanStack11:51 The AI cyber trilogy of the last 12 weeks15:18 Defensive architecture, six layers17:42 What an engineer can do this week18:44 Regulation — U.S. weaker, EU stronger20:25 The maintainer economics problem22:23 Predictions and closingSOURCESTanStack incident postmortem (May 11, 2026)Snyk + Socket — TanStack 42-package compromise analysisSLSA v1.0 specification (slsa.dev)Sigstore project documentationExecutive Orders 14028, 14144, 14306EU Cyber Resilience Act (Regulation 2024/2847)Sonatype — 2025 State of the Software Supply ChainHagendorff et al. — Nature 2026 (LRM-on-LRM jailbreak)UK AISI — GPT-5.5 evaluation (May 7, 2026)Google Threat Intelligence Group — first criminal AI-built 0-day (May 11, 2026)Andres Freund — xz utils backdoor discovery (oss-security)Tidelift — 2024 State of the Open Source Maintainer Report

Episode metadata supplied by the publisher feed · Published May 13, 2026

Embed this episode

NOW PLAYING

The Pipeline Is the Package: SLSA Provenance Failed Its First Real Test

0:00 24:48

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Deep Dive?

This episode is 24 minutes long.

When was this Deep Dive episode published?

This episode was published on May 13, 2026.

Can I download this Deep Dive episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!