logo

Someone published four versions of a fake "tanstack" package in 27 minutes to steal your .env files

ID: 7429eb36-aaf6-57ec-812f-0012c7ae018e

STIX ID: report--7429eb36-aaf6-57ec-812f-0012c7ae018e

Feed Name: Aikido Security's Blog

Threat Score
80/100

Date Published: 2026-04-29

Date Updated: 2026-07-24

...
...

An attacker registered the unscoped npm name "tanstack" and published four malicious releases (2.0.4–2.0.7) on April 29, 2026, embedding a postinstall hook that reads local .env files (including .env.local and variants) and POSTs their contents and system metadata to a Svix webhook, exposing API keys, tokens, and other secrets; the report supplies hashes for the malicious packages, the exfiltration endpoint and source ID, mitigation steps (rotate secrets, inspect lockfiles and CI logs), and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.