What happened
Attacker submitted a malicious PR fork, poisoned GitHub Actions runner cache across fork-trust boundary, extracted OIDC token from runner memory, and published 84 malicious package versions using TanStack's legitimate publishing identity. Payload then stole CI credentials and wrote itself into Claude Code hooks for workstation persistence.