logo

Malicious TanStack Package Abuses Postinstall Script to Steal Developer Secrets

ID: b2229148-5638-5c07-8896-75f2b34a7176

STIX ID: report--b2229148-5638-5c07-8896-75f2b34a7176

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-04

Date Updated: 2026-06-18

Author: Mayura Kathir

...
...

A malicious unscoped npm package impersonating the TanStack ecosystem was published with a hidden postinstall hook (versions 2.0.4–2.0.7) that read .env* files and system metadata and exfiltrated them to a Svix webhook; developers should check lockfiles/node_modules for the affected versions, assume compromise if present, rotate exposed credentials, audit CI/CD builds, and monitor outbound traffic to api.svix.com.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.