Fake TanStack npm Package Exfiltrates Sensitive Developer Data
ID: f66f85d5-ea75-5473-b679-9fe1a4562a70
STIX ID: report--f66f85d5-ea75-5473-b679-9fe1a4562a70
Feed Name: Cyber Press
Threat Score
Researchers detected an active supply-chain attack: a malicious unscoped npm package named "tanstack" impersonated the official @tanstack scope and, via post-install scripts, silently searched for and exfiltrated environment files and sensitive credentials. Multiple malicious versions were pushed in rapid succession; victims are advised that credentials present at install time must be considered compromised and rotated immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
