logo

Fake TanStack npm Package Exfiltrates Sensitive Developer Data

ID: f66f85d5-ea75-5473-b679-9fe1a4562a70

STIX ID: report--f66f85d5-ea75-5473-b679-9fe1a4562a70

Feed Name: Cyber Press

Threat Score
86/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Varshini

...
...

Researchers detected an active supply-chain attack: a malicious unscoped npm package named "tanstack" impersonated the official @tanstack scope and, via post-install scripts, silently searched for and exfiltrated environment files and sensitive credentials. Multiple malicious versions were pushed in rapid succession; victims are advised that credentials present at install time must be considered compromised and rotated immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.