logo

Cybercriminals Abuse Tanstack Package To Target Developer Environments

ID: 6f8bb032-b90e-5b82-b1fc-b2c444876fcc

STIX ID: report--6f8bb032-b90e-5b82-b1fc-b2c444876fcc

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Varshini

...
...

A malicious npm package named "tanstack" impersonated the legitimate TanStack project and published versions 2.0.4–2.0.7 that included a hidden postinstall hook to locate and exfiltrate environment files (.env, .env.local and variants) to a Svix webhook; developers who installed those versions should assume secrets were stolen and must rotate credentials, revoke tokens, and inspect logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.