logo

The TanStack Breach and the Fragility of Trusted Code

ID: 4cd5c71f-a401-582d-be46-5e0a42b4ebc5

STIX ID: report--4cd5c71f-a401-582d-be46-5e0a42b4ebc5

Feed Name: Security Boulevard

Threat Score
85/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Rebecca Kappel

...
...

On May 11, 2026, 42 @tanstack/* packages had malicious versions published (84 artifacts) via a hijacked release pipeline; the malware executed during installation to steal credentials (cloud keys, tokens, SSH keys, etc.). The exposure window was short but the campaign (Mini Shai-Hulud) spread to other maintainers and affected organizations including Mistral AI, UiPath, and at least two OpenAI employee devices; remediation steps include removing affected versions, reviewing lockfiles and CI/CD logs, isolating systems, and rotating credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.