🏷️Topic

Tanstack

2 articles
First tracked: May 12, 2026
Last updated: May 12, 2026

Latest Coverage

Postmortem: TanStack npm supply-chain compromise

↗

TanStack disclosed a multi-vector npm supply-chain compromise affecting 84 malicious package versions across 42 @tanstack/* packages, traced to a PR-wrapping cache-poisoning chain and in-memory OIDC token exfiltration, with deprecation and credential-rotation guidance following rapid external detection.

May 12, 20261%

TanStack NPM Packages Compromised

↗

TanStack npm packages were compromised via a supply-chain attack using optionalDependencies to pull in a malicious git commit; payload exfiltrates credentials and republishes vulnerable packages; GitHub Actions OIDC trusted-publisher config suggests CI workflow compromise; multiple TanStack packages affected with two bad versions each, plus broader ecosystem risk.

May 12, 20261%

Related Entities

🏷️TopicPackage-supply-chain
1
🏷️TopicStepsecurity
4
🏷️TopicNpm
14
📈StockOIDC
4
🏷️TopicGithub Actions
4