Malicious npm Package Brand-Squats TanStack Exfiltrate Developer Secrets
ID: 6e7ff284-0a2e-52d6-b453-7b56447a367f
STIX ID: report--6e7ff284-0a2e-52d6-b453-7b56447a367f
Feed Name: cybersecurityNews.com
A malicious unscoped npm package named “tanstack” (npm/[email protected]–2.0.7) impersonated the legitimate TanStack project and used postinstall hooks to scan for and exfiltrate .env files via an Svix webhook (source ID src_3387PLMB2uhXOBe3Q8sHu, ingest URL https://api.svix.com/ingest/api/v1/source/src_3387PLMB2uhXOBe3Q8sHu/); analysts recommend uninstalling the package, rotating all secrets found in affected .env files, auditing package.json/package-lock.json/yarn.lock for the unscoped package, adding it to registry deny lists, and monitoring outbound traffic to api.svix.com.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
