Postmortem: TanStack NPM supply-chain compromise | Build or Be Replaced
Today: Postmortem: TanStack NPM supply-chain compromise | They Live (1988) inspired Adblocker | If AI writes your code, why use Python? Episode date: 2026-05-12.
Download MP3 →
Build or Replaced
Today: Postmortem: TanStack NPM supply-chain compromise | They Live (1988) inspired Adblocker | If AI writes your code, why use Python? Episode date: 2026-05-12.
Download MP3 →The brainstorming skill is designed for open-ended creative work where requirements need exploration — here the spec is fully defined, including exact structure, stories, format rules, and stats to use. Proceeding directly to the script. JOSH: It's Tuesday, May 12. This is Build or Be Replaced — powered by ScanBrief.dev. I'm Josh, here with Erik Anderson. ERIK: Criminal hackers used AI to find a real zero-day this week. Not theoretical — confirmed. We're going to talk about what that actually means. JOSH: Stick around — Erik's got an AI pro tip at the end about locking down your automated build pipelines. [pause] JOSH: Quick headlines. GitLab cut staff and killed their CREDIT values. They're calling it adapting to the "agentic era." What's the read? ERIK: When a company fires people and buries the culture doc in the same press release, that's a reset, not an evolution. Watch the product roadmap over the next 90 days. That's where the real story is. [beat] JOSH: Hacker News is debating whether Python matters anymore now that AI writes most of the code. ERIK: Python's still the language AI writes in. You still have to read it, debug it, understand what it's doing at 2 AM when something breaks. The job shifted — more code review, less code typing. Fluency still matters. [beat] JOSH: And there's a new paper out on interaction models — real-time multi-modal AI collaboration with human-in-the-loop baked into the architecture from the start. ERIK: That's the right framing. Most people treat human-in-the-loop as a fallback for when AI fails. It's not. It's a first-class architectural decision. You route to a human when confidence drops below threshold — proactively, not as a recovery path. [pause] JOSH: Okay, first deep dive. TanStack — 42 NPM packages compromised, 84 malicious versions published in 6 minutes. How does something like that even happen? ERIK: Three techniques stacked on top of each other. GitHub Actions cache poisoning, a pattern called "Pwn Request" where a fork-based pull request can trigger a workflow with base-repo permissions it shouldn't have, and runtime OIDC token extraction. Those are the short-lived credentials GitHub issues to authenticate Actions workflows mid-run. Stack those three together and you get package publish rights without ever touching a stored secret. JOSH: 6 minutes for 84 versions. That wasn't a human doing that manually. ERIK: Someone built an automated publish pipeline specifically for this attack. They knew which packages to hit, they went fast on purpose — before maintainers could revoke anything. That's a planned operation with a prepared script, not a grab-bag exploit. [beat] JOSH: The report says no credentials were stolen though. Does that matter? ERIK: It's the wrong question. What matters is code execution. Every project that ran npm install and pulled one of those 84 versions potentially executed attacker code — in a build pipeline, in a local dev environment, in a containerized prod deploy. The question isn't what they took. It's what ran. JOSH: So the damage is invisible until it isn't. ERIK: Right. And by the time you know, it's already happened. [beat] JOSH: How do you protect against this if you're running automation like you are? ERIK: First layer: pin your dependencies. Exact versions, not ranges. "1.0.0", not "~1.0.0". Then go further and verify hashes. Every package on NPM and PyPI has a published integrity hash for every version. You fetch it, you compare, you fail fast if anything doesn't match. That catches supply chain tampering, not just version drift. JOSH: Is that expensive to add to an existing pipeline? ERIK: Twenty-five lines of Python. One build step. If your pipeline is already automated, it's an afternoon. [beat] ERIK: The second layer is scope reduction in CI. The OIDC exploit works because most GitHub Actions pipelines are granted way more permission than they actually need. If your runner has package publish rights, cloud credentials, API keys — all in the same workflow — that's a single point of compromise waiting to happen. Minimum permissions, scoped to exactly what each job requires. JOSH: You're running Gandalf on every push. Does it flag that kind of thing? ERIK: Gandalf looks for overly permissive configs, broad secret access, patterns that have caused incidents before. Since April 17th the auto-merger has run 1,215 attempts — 467 merged, 736 blocked. Those 736 aren't failures. That's the guardrail catching what shouldn't ship. Four code changes ran through that overnight and were in production before I had coffee this morning. [beat] JOSH: What's actually getting caught in those 736? ERIK: Bad import paths, dependency version issues, missing error handling, patterns Gandalf recognizes from past incidents across the codebase. Some of them would've been fine in prod. Some of them would've been a 2 AM page. The gate doesn't try to predict which — it reviews everything, and anything it's not confident about doesn't merge. Twelve cases have been escalated to me since April 17th. Those are the ones that needed a human decision. JOSH: Twelve out of 1,215. That's a pretty quiet morning routine. ERIK: That's the whole point of building it that way. [pause] JOSH: Second story. Google confirmed that criminal hackers used AI to find an actual novel software vulnerability. Not leveraging an existing CVE — original vulnerability research, AI-assisted. What changes? ERIK: Nothing changed suddenly. The tools security researchers use to find bugs — static analysis, fuzzing, pattern recognition across large codebases — those are all things frontier models are now genuinely competent at. The gap between "has the knowledge" and "can do the work" closed. And that applies to attackers exactly the same way it applies to defenders. JOSH: How much faster does AI make the research cycle? ERIK: A senior security researcher finding a novel memory corruption bug in a complex codebase might spend weeks. You're reading assembly, writing custom fuzzers, building a mental model of the control flow. With an LLM in the loop, you describe the vulnerability class, hand it the codebase, iterate on hypotheses in hours. The model doesn't replace the expertise — it compresses the iteration time dramatically. [beat] JOSH: You're running 89 services in production right now. Does this change your threat model? ERIK: It changes the timeline assumption. My old mental model was: stay ahead of human attackers moving at human speed. That's done. An attacker's scanner can move as fast as my monitoring pipeline. PrimeBus processed 2,519 events across 9 projects today — my defenders are automated. So are their scanners now. The reaction-time gap is gone. JOSH: So both sides are running automation and the humans are just setting the objectives. ERIK: Right. And that means the quality of your automation matters more than ever. Sloppy automation on the attack side still finds bugs. Sloppy automation on the defense side gives you false confidence, which is worse than nothing. [beat] JOSH: Does this change what Gandalf should be checking for? ERIK: It has to expand. Right now Gandalf is focused on code quality and known-bad patterns. The next layer is configuration hygiene — exposed debug endpoints, overly permissive CORS headers, unvalidated inputs at API boundaries. Those are exactly the patterns an AI scanner excels at finding because they're consistent and recognizable across codebases. If my reviewer isn't catching them, an attacker's tooling might find them first. JOSH: You're building your defender to think like an attacker's scanner. ERIK: That's exactly where this is going. [pause] JOSH: Quick third one — Claude is now fully available on AWS. Full API, managed agents, code execution, the whole platform integrated into AWS billing and IAM. Big deal? ERIK: It's a procurement story more than a technology story. Enterprise teams that are AWS-native had to manage Anthropic credentials outside their existing cloud infrastructure — separate billing, separate IAM, separate audit trails, separate compliance reviews. That friction is now gone. It's in your VPC, your existing dashboard, your established approval process. JOSH: You're not using this. You've got your own setup. ERIK: PrimeRouter handles my LLM routing — multi-provider failover, priority-tier queuing, fleet telemetry. I'm not going through any cloud intermediary. But for teams that have to satisfy compliance requirements or work inside existing cloud procurement contracts, this is the path of least resistance to a frontier model. The model didn't change. The buying motion did. At this stage of the market, distribution matters more than features. [pause] ERIK: This episode is sponsored by Prime Automation Solutions. If you're still doing it manually, we automate it. Also, special on a website — $250. primeautomationsolutions.com [pause] JOSH: Alright, what's the AI pro tip today? ERIK: Wire a hash verification step into any agentic pipeline that installs packages. Before anything executes, call PyPI's or NPM's package API — every published version has an integrity hash. Fetch it, compare it against what's installed, fail the step if they don't match. It's about 25 lines of Python and you can drop it into any existing workflow in an afternoon. ScanBrief scored 35 items across 54 sources this morning and a supply chain attack was one of the top signals. This is the week to add that check. That's your tip. Use it. [pause] JOSH: We also drop daily market picks and automation tips on YouTube — search Build or Be Replaced. [beat] JOSH: One more thing — we started a Discord for builders. If you're shipping AI, automation, or anything that makes a human obsolete — come hang out. Link at buildorbereplaced.dev. ERIK: Post what you built. We'll post what we're building. Real wins, real builds, no fluff. [beat] ERIK: Build or be replaced. JOSH: If you want these signals in your inbox every morning, scanbrief.dev. See you tomorrow.