Daniel Adeboye
4.2K posts

Daniel Adeboye
@AdeboyeDN
multiple hat wearer @northflank. // between updates


SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

engaged💍💕




Just got back from Singapore where we spent the week with one of our partners in the region, @GovTechSG, the lead agency driving the nation's digital transformation. Can confidently say Singapore is having its AI moment, just like here in London. Was a pleasure to meet everyone, and left so deeply impressed by how GovTech is building software at warp speed. The country seems to be building everything else just as fast... I learned the construction crane is the national bird of Singapore. 😆 First time @fr3fou and I ran a hands-on workshop for 200+ developers, helping them onboard onto Northflank. Also a good time to say we're hiring engineers in Singapore. If you know anyone interested in infrastructure and helping companies deploy their most critical workloads to production, please shout.





Jinseoul ranks the top 10 states she visited in Nigeria 💜



Vercel CEO Guillermo Rauch signals IPO readiness as AI agents fuel revenue surge techcrunch.com/2026/04/13/ver…


Confirmed: The hacker “BytetoBreach” published over 3TB or sensitive data. They hacked Remita, Sterling Bank, Zenith Bank, the Oyo State Government, Leadway Assurance, GetBumpa, ABU Zaria, and over 30 Nigerian companies, including government institutions, exposing sensitive data to the public.








