ZeroHour
Product

TanStack npm packages

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

CrowdSec says the TanStack npm supply chain attack let an attacker copy 170 private GitHub repos via a former employee's retained account.

On May 22 an attacker used a GitHub OAuth token from a former CrowdSec employee whose organization access had been kept active, copying about 170 private repositories containing the web console, data science models, and blocklist consensus algorithm. CrowdSec attributes the access to CVE-2026-45321, the May 11 publication of 84 malicious versions of 42 TanStack npm packages that stole GitHub tokens, SSH keys, and cloud credentials from developer machines. The leaked archive also exposed email addresses of 83 users and names, emails, and investment context of 51 potential investors from 2020. The same campaign affected Mistral AI and OpenAI, and the only usable credential found in the leak, an AWS SNS publish token, saw an attempted misuse on August 17.

The Hacker Newsupdated · 15h agofirst · 19h agoData breach in the wild 2 sourcesCVE-2026-45321

Related CVEs

  • Supply chain compromise: credential-stealing code in 42 @tanstack/* npm packages
    CVE-2026-45321 is a supply chain compromise in which 84 malicious versions across 42 @tanstack/* npm packages (including @tanstack/react-router, @tanstack/react-start, @tanstack/history, and related router/start packages) were published to the npm registry on 2026-05-11 between roughly 19:20 and 19:26 UTC, authenticated through TanStack's legitimate GitHub Actions OIDC trusted-publisher binding. The attacker chained three known weakness classes — a pull_request_target 'Pwn Request' misconfiguration, GitHub Actions cache poisoning across the fork-to-base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — allowing publication under a trusted identity without modifying the publish workflow. Each affected package received exactly two malicious versions carrying credential-stealing malware, so developers, CI pipelines, or downstream builds that installed them could have npm, GitHub, and cloud credentials extracted; related reporting (FBI, StepSecurity) links the campaign to stolen cloud credentials and a self-spreading 'Mini Shai-Hulud' worm that also hit packages in other ecosystems such as Mistral AI and Guardrails AI. Exposure is limited to consumers who installed the two malicious versions published per package during the exposure window; other users of these widely deployed libraries were not affected by the malicious publishes. Exploitation is confirmed in the wild: the issue was added to CISA's Known Exploited Vulnerabilities catalog on 2026-05-27 with known ransomware use, and EPSS estimates a 2.3% probability of exploitation in the next 30 days (83rd percentile).
    · tanstack @tanstack/arktype-adapter · tanstack @tanstack/eslint-plugin-router KEV ransomware PoC ×2large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.