TanStack Supply-Chain Attack DNS Indicators
Last updated on:
Applies to: Log360Log360 Cloud
In this page
About the rule
Rule Type
Standard
Rule Description
Detects DNS queries to attacker-controlled infrastructure used by the Mini Shai-Hulud campaign targeting TanStack npm packages.
Severity
Attention
Rule Requirement
Criteria
Action1:
actionname = "DNS Query Executed" AND ( QUERY contains "git-tanstack.com,filev2.getsession.org" )
select Action1.HOSTNAME,Action1.MESSAGE,Action1.PROCESSNAME,Action1.QUERY,Action1.STATUSCODE,Action1.RESULT
Detection
Execution Mode
continuous
Log Sources
Windows
Author
@Leonardo Gasparini


