logo

84 TanStack npm Packages Hacked in Ongoing Supply-Chain Attack Targeting CI Credentials

ID: 17951002-9805-51c9-8f8e-e438a21d1dbc

STIX ID: report--17951002-9805-51c9-8f8e-e438a21d1dbc

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Guru Baran

...
...

High-severity supply-chain compromise: 84 TanStack npm package versions were published with an obfuscated credential‑stealing payload (~2.3 MB router_init.js) that targets CI environments (GitHub Actions) and can exfiltrate AWS/GCP/Kubernetes/HashiCorp Vault credentials, GitHub tokens, SSH keys, and .npmrc contents. The attacker used a malicious optionalDependency pointing to a standalone commit that executes via a prepare lifecycle hook and gained publisher rights via chained GitHub Actions abuses (pull_request_target “Pwn Request”, cache poisoning, and OIDC memory extraction); TanStack deprecated affected versions and recommends rotating credentials, auditing logs, purging caches, and reinstalling from clean lockfiles.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.