logo

Supply Chain Siege: 84 TanStack Packages Compromised to Steal GitHub Secrets

ID: 9f166336-1913-5324-ab7a-a1696adcae07

STIX ID: report--9f166336-1913-5324-ab7a-a1696adcae07

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Ddos

...
...

Socket Threat Research disclosed a high-impact supply-chain compromise affecting 84 @tanstack npm packages: attackers added a ~2.3 MB obfuscated credential stealer (router_init.js) and a GitHub-hosted optional dependency with a prepare lifecycle hook that executes tanstack_runner.js during installation, aiming to harvest GITHUB* environment variables (CI/Actions tokens). The report urges immediate auditing of lockfiles for the malicious dependency, rotation of GitHub/CI secrets and tokens, and clean rebuilds to remove the injected code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.