84 TanStack npm Packages Compromised in Ongoing Supply-Chain Attack Targeting CI Credentials
ID: c969c99d-e894-5c48-84e3-3a499e377411
STIX ID: report--c969c99d-e894-5c48-84e3-3a499e377411
Feed Name: Cyber Press
A widespread supply-chain breach compromised 84 TanStack npm packages (including high-download modules) by inserting an obfuscated worm (router_init.js / tanstack_runner.js) that steals CI and cloud credentials (GitHub Actions tokens, AWS metadata, Kubernetes service accounts, Vault) and exfiltrates data via the Session P2P network; attackers abused a pull_request_target GitHub Actions pattern to obtain runtime OIDC tokens to publish poisoned updates—developers should audit for unexpected scripts, rotate credentials, and consume the provided IOCs for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
