Malicious Tanstack Package Uses Postinstall Script to Steal Developer Environment Files
ID: becbeb4c-8299-5457-8593-04bdd75ab5e0
STIX ID: report--becbeb4c-8299-5457-8593-04bdd75ab5e0
Feed Name: cybersecurityNews.com
A malicious unscoped npm package named "tanstack" impersonated the legitimate TanStack project and, during a 27-minute window on 2026-04-29 (versions 2.0.4–2.0.7), used postinstall hooks to collect .env* files and other sensitive developer/environment data, exfiltrating it via the Svix webhook relay; the report includes SHA256 IOCs for each malicious version, detection steps (search lockfiles, monitor outbound calls to api.svix.com, check CI install logs), and remediation guidance (rotate AWS/GitHub/npm/database/API keys, audit CloudTrail, revoke tokens).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
