open-source/ supply-chain · javascript

Mantine-datatable owner account suspended after supply-chain breach

The maintainer’s GitHub account was blocked on June 5, 2026, affecting versions 2.5‑2.7 of the library.

Mantine-datatable owner account suspended after supply-chain breach

Mantine-datatable’s maintainer account was suspended on June 5, 2026, after a compromise that let attackers inject malicious code into the package. The breach impacts released versions 2.5.0 through 2.7.3, which are still pulled by downstream projects.

The library is widely used in React UI stacks, so the incident could force developers to audit or roll back dependencies. The maintainer posted a brief note on the discussion thread, acknowledging the suspension and promising a clean‑up, but gave no timeline for reinstatement.

If you rely on Mantine‑datatable, lock the dependency to a safe version or switch to an alternative until the account is restored. The incident underscores how a single compromised maintainer account can ripple through the open‑source supply chain.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →