📣 Send us your press release
Site updates every 15 minutes
Technology

Supply chain attack on TanStack compromises 42 npm packages

On May 11, 2026, 84 compromised versions of 42 `@tanstack/*` packages were discovered on the npm package manager, containing credential-stealing malware. The attack targeted popular web development tools.

28 September 2026
Supply chain attack on TanStack compromises 42 npm packages

The JavaScript development ecosystem was disrupted on May 11, 2026, with the discovery of a supply chain attack targeting TanStack's packages. Security researchers identified a total of 84 compromised versions across 42 different @tanstack/* packages on the npm package manager. These packages contained malware designed to steal developer credentials and sensitive information.

Following the detection of the malicious versions, the TanStack team announced that the affected packages have been marked as deprecated. However, the exact number of installations remains unknown, leaving uncertainty about the potential extent of the malware's spread. Security experts strongly advise all users to rotate their credentials immediately.

TanStack is known for its popular open-source tools, including TanStack Query, a state management utility. While several packages were compromised, the development team confirmed that packages such as @tanstack/query*, @tanstack/table*, and @tanstack/form* were not affected. A detailed list of the compromised packages, including @tanstack/router-cli and @tanstack/solid-start, has been published in a GitHub security advisory.

The malware employed in this attack aims to steal credentials from various sources, including AWS instance metadata, GitHub tokens, and SSH keys. The security firm Socket has provided guidance on the recommended order for developers to rotate their credentials, prioritizing npm tokens, GitHub PATs, and AWS credentials. This incident is part of a broader campaign known as "Mini Shai-Hulud," which has also targeted other npm and PyPI packages.

Original source: heise.de