logo

Malicious Tanstack Package Uses Postinstall Script to Steal Developer Environment Files

ID: becbeb4c-8299-5457-8593-04bdd75ab5e0

STIX ID: report--becbeb4c-8299-5457-8593-04bdd75ab5e0

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

A malicious unscoped npm package named "tanstack" impersonated the legitimate TanStack project and, during a 27-minute window on 2026-04-29 (versions 2.0.4–2.0.7), used postinstall hooks to collect .env* files and other sensitive developer/environment data, exfiltrating it via the Svix webhook relay; the report includes SHA256 IOCs for each malicious version, detection steps (search lockfiles, monitor outbound calls to api.svix.com, check CI install logs), and remediation guidance (rotate AWS/GitHub/npm/database/API keys, audit CloudTrail, revoke tokens).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.