EPISODE · May 13, 2026 · 24 MIN
The Pipeline Is the Package: SLSA Provenance Failed Its First Real Test
from Deep Dive · host Deep Dive
May 11, 2026. Between 19:20 and 19:26 UTC. Six minutes. An attacker published 84 malicious versions across 42 TanStack packages on npm — including React Router with 12.7 million weekly downloads. Every malicious version was signed with valid SLSA build provenance. Every check npm performs passed. The build pipeline that produced the malicious artifacts was the real TanStack pipeline. The attestation wasn't lying.This episode walks the six minutes, what SLSA was supposed to prevent versus what it actually prevents, the six-year arc from SolarWinds Orion to TanStack, and the AI cyber trilogy of the last twelve weeks that makes this the wrong moment for any of it to fail.The attack chain minute by minute. Pwn Request via pull request target. Cache poisoning across the workflow boundary. OIDC token theft from the GitHub Actions runner. Eighty-four npm publishes in sixty seconds, every one producing valid SLSA provenance — because the publishes really came from the official TanStack workflow on the main branch on a hardened build platform. SLSA L3 verified everything it was designed to verify. It just doesn't verify that the inputs to the build script were the intended inputs.Then the lineage. SolarWinds. Codecov. node-ipc. xz utils Jia Tan caught by a Microsoft engineer who noticed half a second of SSH latency. tj-actions. Shai-Hulud. Each moved the trust failure up the stack.And the AI cyber trilogy. Hagendorff in Nature: LRMs jailbreaking LRMs at 97 percent ASR. UK AISI on GPT-5.5 at 71.4 percent expert cyber tasks. Google Threat Intelligence Group confirming the first criminal AI-built zero-day on the same day TanStack got hit. Frontier cyber offense doubling every 3.4 months.Defense in six layers: SLSA provenance, Sigstore, SBOMs, OIDC trusted publishing across npm/PyPI/RubyGems/crates.io, pre-publish package analysis (the layer that actually caught TanStack), runtime detection. What an engineer can do this week: audit pull-request-target workflows, pin third-party actions to commit SHAs, namespace caches by workflow.Plus regulation (U.S. weaker after EO 14306, EU stronger via the Cyber Resilience Act), the maintainer economics problem nobody is fixing, and five predictions.The thesis: the frameworks help. What actually catches the next one is somebody paying attention to a five-times tarball-size anomaly.RELATED EPISODESThe Palo Alto CVE Cluster — sister cyber episode; Klarich's 3-to-5-month window quoted on the recordThe ShinyHunters SSO Breach — SaaS-side attack surface as the trust chain shifted from packages to pipelinesClaude Mythos — the model class behind Google TIG's first criminal AI-built zero-day on May 11The AI Layoff Gap — cybersecurity tributary; security-analyst postings -25.88% as the canary cohortCHAPTERS00:00 Cold open — the 6-minute TanStack window00:47 Show intro and roadmap01:18 Callback — LiteLLM, the same pattern weeks earlier01:58 The attack chain, minute by minute05:56 SLSA — what it actually guarantees08:12 The 6-year lineage — SolarWinds to TanStack11:51 The AI cyber trilogy of the last 12 weeks15:18 Defensive architecture, six layers17:42 What an engineer can do this week18:44 Regulation — U.S. weaker, EU stronger20:25 The maintainer economics problem22:23 Predictions and closingSOURCESTanStack incident postmortem (May 11, 2026)Snyk + Socket — TanStack 42-package compromise analysisSLSA v1.0 specification (slsa.dev)Sigstore project documentationExecutive Orders 14028, 14144, 14306EU Cyber Resilience Act (Regulation 2024/2847)Sonatype — 2025 State of the Software Supply ChainHagendorff et al. — Nature 2026 (LRM-on-LRM jailbreak)UK AISI — GPT-5.5 evaluation (May 7, 2026)Google Threat Intelligence Group — first criminal AI-built 0-day (May 11, 2026)Andres Freund — xz utils backdoor discovery (oss-security)Tidelift — 2024 State of the Open Source Maintainer Report
Embed this episode
NOW PLAYING
The Pipeline Is the Package: SLSA Provenance Failed Its First Real Test
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.