Syntax - Tasty Web Development Treats
Syntax - Tasty Web Development Treats
Wes Bos & Scott Tolinski - Full Stack JavaScript Web Developers
1004: TanHacked
23 minutes Posted May 13, 2026 at 11:00 am.
Welcome to Syntax!
Understanding the Shai-Hulud Worm
Mechanics of the Attack: GitHub Actions and Cache
Brought to you by Sentry.io
Propagation and Impact of the Worm
Preventative Measures for Developers
The Role of Package Managers in Security
Using Dev Containers
Conclusion and Final Thoughts
0:00
23:16
Download MP3
Show notes
Scott and Wes break down the “Mini Shai-Hulud” supply chain attack that compromised TanStack and other popular npm packages through a clever GitHub Actions cache poisoning exploit; a self-propagating worm that stole credentials and persisted through Claude Code hooks and VS Code tasks. They also cover how developers can protect themselves using pnpm’s security defaults, dev containers, and other practical defenses.
Show Notes
Post Mortem of Shai Hulud Attack
How the attack happened
Who Was Involved in the Attack
Several npm latest releases are compromised
Socket.dev
Step Security
Dead Man’s Switch
Block Exotic Subdeps
Why You Should Use Dev Containers
Scott Tolinski’s Security Review
Sentry has Skills!
Hit us up on Socials!
Syntax: X Instagram Tiktok LinkedIn Threads
Wes: X Instagram Tiktok LinkedIn Threads
Scott: X Instagram Tiktok LinkedIn Threads
Randy: X Instagram YouTube Threads