U.S. CISA adds Daemon Tools, TanStack, and Nx Console flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-45321 | Supply chain compromise: credential-stealing code in 42 @tanstack/* npm packages CVE-2026-45321 is a supply chain compromise in which 84 malicious versions across 42 @tanstack/* npm packages (including @tanstack/react-router, @tanstack/react-start, @tanstack/history, and related router/start packages) were published to the npm registry on 2026-05-11 between roughly 19:20 and 19:26 UTC, authenticated through TanStack's legitimate GitHub Actions OIDC trusted-publisher binding. The attacker chained three known weakness classes — a pull_request_target 'Pwn Request' misconfiguration, GitHub Actions cache poisoning across the fork-to-base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — allowing publication under a trusted identity without modifying the publish workflow. Each affected package received exactly two malicious versions carrying credential-stealing malware, so developers, CI pipelines, or downstream builds that installed them could have npm, GitHub, and cloud credentials extracted; related reporting (FBI, StepSecurity) links the campaign to stolen cloud credentials and a self-spreading 'Mini Shai-Hulud' worm that also hit packages in other ecosystems such as Mistral AI and Guardrails AI. Exposure is limited to consumers who installed the two malicious versions published per package during the exposure window; other users of these widely deployed libraries were not affected by the malicious publishes. Exploitation is confirmed in the wild: the issue was added to CISA's Known Exploited Vulnerabilities catalog on 2026-05-27 with known ransomware use, and EPSS estimates a 2.3% probability of exploitation in the next 30 days (83rd percentile). Do: Audit lockfiles and CI logs for the affected @tanstack/* packages' versions published during the 2026-05-11 ~19:20-19:26 UTC window; if found, reinstall from clean versions per the TanStack postmortem (tanstack.com/blog/npm-supply-chain-compromise-postmortem) and rotate exposed credentials (npm tokens, GitHub PATs/secrets, cloud keys), treating any cached CI artifacts as suspect. Apply mitigations per vendor instructions and CISA BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable, and remediate the underlying CI weaknesses (pull_request_target handling, Actions cache hygiene, and OIDC token handling) to prevent recurrence. | 9.6 | 2% | KEV ransomware PoC ×2 |
| large~100,000+ downstream installs/CI runs (estimate) | |
| CVE-2026-48027 | Malicious Code Embedded in Nx Console VS Code Extension 18.95.0 CVE-2026-48027 is a supply-chain compromise in which version 18.95.0 of Nx Console, the Visual Studio Code UI for the Nx and Lerna build tools, was published with embedded malicious code (CWE-506). The compromised release was live on the Visual Studio Marketplace for roughly 18 minutes (12:30-12:48 UTC) and on OpenVSX for about 36 minutes (12:33-13:09 UTC) on 19 May 2026, so developers whose clients pulled the update during those windows had the malicious extension installed. An attacker gains code execution on developer workstations and used it to steal cloud and CI credentials; the compromise has been tied to a breach of GitHub internal repositories and is associated with ransomware activity. Only users who installed Nx Console 18.95.0 are affected, and version 18.100.0 is not compromised. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 27 May 2026 with known ransomware use, and public analysis is available from StepSecurity. Do: Upgrade to Nx Console 18.100.0 immediately; if 18.95.0 was installed on 19 May 2026, treat local secrets as compromised and rotate GitHub tokens, cloud and CI credentials, npm tokens, and SSH keys on affected machines, and review repositories and pipelines for tampering. Follow CISA KEV/BOD 22-01 required actions and review the StepSecurity blog post for indicators of compromise. | 9.3 | 2% | KEV ransomware PoC |
| moderatelikely tens of thousands of developer workstations (the subset of Nx Console's roughly one-million-install developer base whose clients auto-updated to 18.95.0… | |
| CVE-2026-8398 | Trojanized Installer Backdoor in DAEMON Tools Lite (Supply Chain Compromise) CVE-2026-8398 (CWE-506, embedded malicious code) is a supply chain compromise in which attackers gained access to AVB Disc Soft's build or distribution infrastructure and trojanized the official Windows installers of DAEMON Tools Lite versions 12.5.0.2421 through 12.5.0.2434, distributed from the legitimate site daemon-tools.cc between approximately April 8 and May 5, 2026. The flaw is triggered by installing or running one of these tampered builds, which shipped backdoored copies of DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe digitally signed with the vendor's legitimate code-signing certificate, allowing them to bypass signature-based detection. Once executed, the embedded backdoor gives attackers a trusted foothold and code execution on the affected Windows host, potentially enabling credential theft, further compromise, or ransomware follow-on activity (ransomware linkage currently unknown). Anyone who downloaded and installed DAEMON Tools Lite from the official site during the affected window is impacted; users with other or older builds are not part of this trojanized distribution. The issue was added to CISA's Known Exploited Vulnerabilities catalog on 2026-05-27, confirming exploitation in the wild, and a public technical write-up is available via Kaspersky's Securelist. Do: Identify hosts that installed DAEMON Tools Lite 12.5.0.2421–12.5.0.2434 from daemon-tools.cc during the affected window; remove/reinstall the software from a clean, current build obtained from the vendor and verify the signatures of DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. Because the trojanized binaries were validly signed, treat affected systems as potentially compromised and hunt for persistence, anomalous process activity, and C2 traffic associated with the backdoor. Federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product by the KEV deadline (listed 2026-05-27). | 9.3 | 1% | KEV PoC |
| largeplausibly ~100,000–1,000,000 Windows installs of the affected builds during the ~4-week trojanized distribution window |
Full article345 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Daemon Tools, TanStack, and Nx Console flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities (KEV) catalog.
Below are the flaws added to the catalog:
- CVE-2026-8398 (CVSS score of ver. 4.0 of 9.3) Daemon Tools Lite Embedded Malicious Code Vulnerability
- CVE-2026-45321 (CVSS score of ver. 3.1 of 9.5) TanStack Unspecified Vulnerability
- CVE-2026-48027 (CVSS score of ver. 4.0 of 9.3) Nx Console Embedded Malicious Code Vulnerability
The first flaw, tracked as CVE-2026-8398, is a supply chain attack that compromised official DAEMON Tools Lite installers distributed from the vendor’s website between April and May 2026. Attackers trojanized three signed binaries after breaching AVB Disc Soft’s build or distribution systems. Because the malicious files carried legitimate code-signing certificates, the installers appeared trustworthy and could evade many security checks.
The second flaw, tracked as CVE-2026-45321, is a supply chain attack that hit 42 @tanstack npm packages after attackers abused GitHub Actions and the trusted-publisher workflow. Using cache poisoning, a pull_request_target misconfiguration, and OIDC token theft from the runner’s memory, they published 84 malicious package versions containing credential-stealing malware under TanStack’s legitimate identity.
The third issue, tracked as CVE-2026-48027, involves a malicious version of the Nx Console extension, version 18.95.0, briefly published to Visual Studio Marketplace and OpenVSX on May 19, 2026. The compromised release remained available for up to 36 minutes before removal. Nx Console 18.100.0 is clean, and users should upgrade immediately to remediate the issue.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities by June 10, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/192776/security/u-s-cisa-adds-daemon-tools-tanstack-and-nx-console-flaws-to-its-known-exploited-vulnerabilities-catalog.html