# Dependabot bump တစ်ခုက worm တစ်ခုကို ထုတ်ပြန်ခဲ့ပါတယ်။ packages ၂၂ ခု။

Published: 2026-09-17

ဘော့တ်တစ်ခုက pull request တစ်ခုကို ဖွင့်ပါတယ်။ လူတစ်ဦးက ၂၄ မိနစ်အကြာမှာ ပေါင်းစပ်လိုက်ပါတယ်။ အဲဒီနောက် ၉၅ မိနစ်အကြာမှာ worm တစ်ခုက သူ့ CI မှာ တွေ့ခဲ့တဲ့ token တစ်ခုနဲ့ သူ့နာမည်အောက်မှာ သူ့ npm packages ၂၂ ခုရဲ့ မူကွဲဆိုး ၁၁၀ ခုကို ထုတ်ပြန်ခဲ့ပါတယ်။

Canonical: https://thedailydiff.dev/my/video/2026-09-17-dependabot-tanstack/

## ဤဗီဒီယိုတွင် ဖော်ပြထားသောအရာများ

- ဘော့တ်တစ်ခု၊ လူတစ်ဦး၊ worm တစ်ခု
- ဘယ်လိုဖြစ်ခဲ့သလဲ၊ npm က ဘာလို့ ခွင့်ပြုခဲ့သလဲ၊ ဘယ်သူ့မှာ အပြစ်ရှိသလဲ
- အချိန်ဇယား- အဆိပ်သင့် cache
- ၂၁:၄၈ — Dependabot bump
- ဘာကြောင့် အလုပ်လုပ်သလဲ

## အခန်းများ

- 0:00 ဘော့တ်တစ်ခု၊ လူတစ်ဦး၊ worm တစ်ခု
- 0:20 ဘယ်လိုဖြစ်ခဲ့သလဲ၊ npm က ဘာလို့ ခွင့်ပြုခဲ့သလဲ၊ ဘယ်သူ့မှာ အပြစ်ရှိသလဲ
- 0:30 အချိန်ဇယား- အဆိပ်သင့် cache
- 1:15 ၂၁:၄၈ — Dependabot bump
- 1:50 ဘာကြောင့် အလုပ်လုပ်သလဲ
- 2:20 git blame
- 2:45 ထိခိုက်မှုပမာဏ
- 3:00 ဆုံးဖြတ်ချက်

## ဘာသာပြန်ထားသော စာသားမှတ်တမ်း

မူရင်း အင်္ဂလိပ်စကားပြောမှ ဘာသာပြန်ထားသည်။ ရရှိနိုင်သော အသံနှင့် စာတန်းထိုးများကို YouTube မှ ထိန်းချုပ်ထားသည်။

### ဘော့တ်တစ်ခု၊ လူတစ်ဦး၊ worm တစ်ခု

0:00 ဘော့တ်တစ်ခုက pull request တစ်ခုကို ဖွင့်ပါတယ်။ လူတစ်ဦးက ၂၄ မိနစ်အကြာမှာ ပေါင်းစပ်လိုက်ပါတယ်။ ၉၅ မိနစ်အကြာမှာ worm တစ်ခုက ထုတ်ပြန်ခဲ့ပါတယ်။ သူ့ packages ရဲ့ မူကွဲ ၁၁၀ ခုကို သူ့အဖြစ်နဲ့ပါ။ TanStack ရဲ့ postmortem မှာ upstream အချိန်မှတ်တမ်းတွေရှိပြီး downstream ထိန်းသိမ်းသူရဲ့ မှာ ကျန်တာတွေရှိပါတယ်။ Hacker News က ၁၁၀၀ မှတ်နဲ့ Mini Shai-Hulud ဆိုတဲ့ နာမည်ကို ပေးထားပါတယ်။ ဘယ်လိုဖြစ်သလဲ၊ npm က ဘာလို့ ခွင့်ပြုသလဲ၊ ဘယ်သူ့မှာ အပြစ်ရှိသလဲ။ Shai-Hulud။ ဘယ်လိုဖြစ်သလဲ၊ npm က ဘာလို့ ခွင့်ပြုသလဲ၊ ဘယ်သူ့မှာ အပြစ်ရှိသလဲ။

### ဘယ်လိုဖြစ်ခဲ့သလဲ၊ npm က ဘာလို့ ခွင့်ပြုခဲ့သလဲ၊ ဘယ်သူ့မှာ အပြစ်ရှိသလဲ

0:21 ဒါက The Daily Diff, postmortem ပါ။ မေလ ၁၁ ရက်၊ မနက်ပိုင်း။ နာမည်ပြောင်းထားတဲ့ fork တစ်ခုက TanStack Router ကို pull request တစ်ခု ဖွင့်ပါတယ်။ တစ်နာရီအတွင်း ပိတ်လိုက်ပေမယ့် benchmark workflow တစ်ခုက သူ့ code ကို run ပြီးပါပြီ။

### အချိန်ဇယား- အဆိပ်သင့် cache

0:33 release workflow က အသုံးပြုမယ့် key အောက်မှာ အဆိပ်သင့် cache တစ်ခုကို သိမ်းဆည်းခဲ့ပါတယ်။ တစ်ဆယ့်ကိုးနာရီနှစ်ဆယ်မိနစ်။ တရားဝင်ပေါင်းစပ်မှုတစ်ခုက release ကို run ပါတယ်။ cache ပြန်ရောက်လာပြီး binary တစ်ခုက runner ရဲ့ memory ကို ဖတ်ပါတယ်။ publish token ကို ရယူပြီး packages ၄၂ ခုမှာ မူကွဲ ၈၄ ခုကို ထုတ်ပြန်ပါတယ်။ တရားဝင် provenance နဲ့ပါ။ စမ်းသပ်မှုတွေ ကျရှုံးသွားတယ်။ ဒါပေမယ့်လည်း ထုတ်ပြန်လိုက်ပါတယ်။ တစ်ဆယ့်ကိုးနာရီလေးဆယ့်ခြောက်မိနစ်မှာ StepSecurity သုတေသီတစ်ဦးက ပြဿနာကို တင်ပြပါတယ်။ ကိုးနာရီ UTC မှာ အရာအားလုံးကို deprecated လုပ်ပြီး advisory ကို ထုတ်ပြန်ပါတယ်။

0:55 Deprecated ဆိုတာ မပျောက်သွားပါဘူး။ npm က မှီခိုသူတွေရှိတဲ့ ဘာကိုမှ unpublish လုပ်ဖို့ ငြင်းဆိုပါတယ်။ ဒါကြောင့် နာရီပေါင်းများစွာ install လုပ်နိုင်ဆဲပါပဲ။ နှစ်ဆယ့်တစ်နာရီလေးဆယ့်ရှစ်မိနစ်။ ကြယ် ၉ ပွင့်အဆင့်ရှိ လေကြောင်းဒေတာ project တစ်ခုမှာ Dependabot က သူ့ရဲ့ ပုံမှန် pull request ကို ဖွင့်ပါတယ်။ dev-dependencies group ကို bump လုပ်ပြီး ၁၃ ခု update လုပ်ပါတယ်။ နှစ်ခုက အဆိပ်သင့် TanStack ဗားရှင်းတွေပါ။ နှစ်ဆယ့်နှစ်နာရီဆယ့်နှစ်မိနစ်- ပေါင်းစပ်လိုက်ပါတယ်။ publish workflow က token in scope နဲ့ npm C-I ကို run ပါတယ်။

### ၂၁:၄၈ — Dependabot bump

1:15 prepare script က ဖတ်ပြီး နှစ်ဆယ့်နှစ်နာရီဆယ့်ခုနစ်မိနစ်မှာ worm က သူ့အဖြစ် ထုတ်ပြန်ပါတယ်။ token ရောက်ရှိတဲ့ package တိုင်းရဲ့ မူကွဲ ၅ ခုစီ၊ အဟောင်း side project တစ်ခုတောင် ပါပါတယ်။ အရာအားလုံးအတွက် classic token တစ်ခုပါ။ မိနစ် ၉၅ မိနစ်အတွင်း မူကွဲ ၁၁၀ ခု။ သူ့ကို သန်းခေါင်ကျော်မှ အီးမေးလ်နဲ့ အကြောင်းကြားပါတယ်။ ဘာကြောင့် အလုပ်လုပ်သလဲ။ တစ်- npm install က သူစိမ်းတွေရဲ့ lifecycle scripts တွေကို default အားဖြင့် run ပါတယ်။ ပြီးတော့ git dependency ရဲ့ prepare script ကပါ ပါပါတယ်။

1:39 နှစ်- worm က တစ်ခုတည်းကို လိုချင်ပါတယ်။ ဒုတိယ authentication factor မပါဘဲ publish လုပ်နိုင်တဲ့ token တစ်ခုပါ။ ပြီးတော့ အဲဒီ maintainer က ဘာတွေပိုင်ဆိုင်သေးလဲဆိုတာ registry ကို မေးပါတယ်။ ပြီးတော့ သူ့ကိုယ်သူ ထည့်ပြီး အားလုံးကို ပြန်လည်ထုတ်ပြန်ပါတယ်။ သုံး- chain မှာ လူတစ်ယောက်မှ မပါဝင်ပါဘူး။

### ဘာကြောင့် အလုပ်လုပ်သလဲ

1:51 ဘော့တ်တစ်ခုက အဆိုပြုတယ်၊ pipeline က install လုပ်တယ်၊ ပြီးတော့ worm က အကျိုးပြန်ပြုတယ်- သူ့ရဲ့ dead-drop branches တွေကို dependabot slash github-actions slash fremen လို့ နာမည်ပေးထားပါတယ်။ git blame။ npm ရဲ့ install model၊ ၅၅ ရာခိုင်နှုန်း- install လုပ်တဲ့အခါ scripts တွေ run တယ်၊ deprecated က install လုပ်နိုင်ဆဲ၊ two-factor-bypass tokens တွေ ရှိနေဆဲ။ TanStack ရဲ့ CI၊ ၂၅ ရာခိုင်နှုန်း- cache ကို write access ရှိတဲ့ unaudited pull request target workflow တစ်ခုက fork code ကို run နေခြင်း။ bump အကျင့်၊ ၁၅ ရာခိုင်နှုန်း- ၂၄ မိနစ်အတွင်း update ၁၃ ခု ပေါင်းစပ်ခဲ့ခြင်း၊ အခန်းထဲမှာ token ရှိနေခြင်း။

2:17 Dependabot၊ ၅ ရာခိုင်နှုန်း- worm က သူ့ယူနီဖောင်းကို ဝတ်ထားလောက်အောင် ယုံကြည်ရခြင်း။

### git blame

2:20 ထိခိုက်မှုပမာဏ- TanStack packages ၄၂ ခု။ ကြယ် ၉ ပွင့် project တစ်ခုကနေ downstream ၂၂ ခု။ worm က Mistral ကို ရောက်တာနဲ့ ecosystem တစ်ခုလုံးမှာ ၁၆၀ ကျော်။ upstream version တိုင်းမှာ တရားဝင်လက်မှတ်ပါရှိပါတယ်- တရားဝင် pipeline က တည်ဆောက်ထားတာပါ။ မှန်ပါတယ်။ ဆုံးဖြတ်ချက်, postmortem: SHIP IT။ ထိန်းသိမ်းသူ နှစ်ဦးစလုံးက တစ်ရက်အတွင်း အချိန်မှတ်တမ်းပါ postmortems တွေ တင်ပါတယ်။ သုံးရက်အတွင်းမှာတော့ downstream pipeline က ignore-scripts နဲ့ install လုပ်ပါတယ်။ build ကို publish ကနေ ခွဲထုတ်ပြီး long-lived token ကို ဖြုတ်ချလိုက်ပါတယ်။

### ထိခိုက်မှုပမာဏ

2:47 npm ရဲ့ defaults တွေက မပြောင်းလဲသေးပါဘူး။ တနင်္လာနေ့- install လုပ်တဲ့အခါ ignore-scripts နဲ့ publish token ကို run တဲ့ job ကနေ ထုတ်ပစ်လိုက်ပါ။ သင်ပြောခွင့်မရသေးတဲ့ ဖြစ်စဉ်ကို comment မှာပဲဖြစ်ဖြစ် thedailydiff.dev မှာပဲဖြစ်ဖြစ် ကျွန်တော့်ဆီ ပို့ပေးပါ။ in the comments, or at thedailydiff.dev. ဒီနေ့အတွက် diff ကတော့ ဒါပါပဲ။

### ဆုံးဖြတ်ချက်

3:00 ကျွန်တော် Axrisi က Niko ပါ။ တာဝန်ယူမှုရှိရှိ ပေါင်းစပ်ပါ။

## ရင်းမြစ်များ

- [TanStack postmortem (Tanner Linsley, May 11, refined May 15)](https://tanstack.com/blog/npm-supply-chain-compromise-postmortem) — tanstack.com
- [TanStack "Hardening TanStack After the npm Compromise" (May 12)](https://tanstack.com/blog/incident-followup) — tanstack.com
- [TanStack/router#7383 — the StepSecurity detection issue](https://github.com/TanStack/router/issues/7383) — github.com
- [Downstream incident post, @squawk/\* (May 12)](https://github.com/neilcochran/squawk/discussions/251) — github.com
- [Downstream hardening post (May 14)](https://github.com/neilcochran/squawk/discussions/264) — github.com
- [The Dependabot PR #246 (opened 21:48 UTC, merged 22:12)](https://github.com/neilcochran/squawk/pull/246) — github.com
- [@tan\_stack advisory post, 21:19 UTC](https://x.com/tan_stack/status/2053948103766716630) — x.com
- [StepSecurity — worm internals, bypass\_2fa search, Dependabot-style branch names](https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem) — www.stepsecurity.io
- [Socket](https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack) — socket.dev
- [Aikido — "over 160 packages, including Mistral"](https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised) — www.aikido.dev
- [Hacker News (1,097 points)](https://news.ycombinator.com/item?id=48100706) — news.ycombinator.com
