Mantine-datatable (and others) compromised – owner account suspended
- Security
- Open Source
- Developer Tools
- Infrastructure
The post is a GitHub discussion from the maintainer of mantine-datatable saying his account was compromised, his account then got suspended, and malicious payloads remained published while he was locked out of fixing them. That turns a repo compromise into a supply-chain problem. Users cannot tell whether they are just dealing with stolen source code or with attacker-controlled updates landing in packages they already trust.
If your build or CI pulls from GitHub repos you do not tightly control, assume account compromise can turn into package compromise fast. Audit any auto-executing GitHub Actions and rotate tokens or secrets exposed to affected repos before waiting for platform support to catch up.
- github.com
- Discuss on HN