Someone published four versions of a fake "tanstack" package in 27 minutes to steal your .env files
ID: 7429eb36-aaf6-57ec-812f-0012c7ae018e
STIX ID: report--7429eb36-aaf6-57ec-812f-0012c7ae018e
Feed Name: Aikido Security's Blog
An attacker registered the unscoped npm name "tanstack" and published four malicious releases (2.0.4–2.0.7) on April 29, 2026, embedding a postinstall hook that reads local .env files (including .env.local and variants) and POSTs their contents and system metadata to a Svix webhook, exposing API keys, tokens, and other secrets; the report supplies hashes for the malicious packages, the exfiltration endpoint and source ID, mitigation steps (rotate secrets, inspect lockfiles and CI logs), and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
