logo

“TanStack”: Malicious Name-Squatting Campaign Steals Environment Secrets

ID: 55137d72-b486-504c-9082-4a1739141122

STIX ID: report--55137d72-b486-504c-9082-4a1739141122

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Ddos

...
...

**Supply-chain npm package exfiltrated environment secrets:** A malicious unscoped package published as `tanstack` (v2.0.4–2.0.7) included a postinstall.cjs that collected .env files and sent them via Svix webhooks; the actor iterated four rapid releases to test and optimize exfiltration and stealth. Immediate actions recommended are to check installs/package-locks, revoke exposed tokens (AWS, GitHub, npm), and audit logs and network traffic for api.svix.com.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.