Attackers compromised TanStack’s npm release pipeline and published 84 malicious versions across 42 @tanstack/* packages, an incident tracked as CVE-2026-45321 with a CVSS score of 9.6. The intrusion chained a vulnerable GitHub Actions pull_request_target workflow, cache poisoning across the fork-to-base trust boundary, and theft of an OIDC token from runner memory, allowing the adversary to push malware under a trusted identity. The poisoned releases carried valid SLSA Build Level 3 provenance, showing that the builds originated from the legitimate pipeline even though that pipeline had been subverted.
The malicious packages used npm lifecycle execution and injected components including a fake @tanstack/setup dependency and a payload file named router_init.js to exfiltrate secrets from CI/CD systems and developer machines. Reporting tied the activity to the Shai-Hulud malware family and described a two-stage payload that harvested credentials, scraped GitHub Actions runner memory, exfiltrated data through multiple channels, and attempted self-propagation with stolen maintainer tokens; related package abuse was also noted in ecosystems including @opensearch-project/opensearch, @uipath/*, and @redhat-cloud-services. Defenders were urged to treat any affected installation as a likely credential compromise and to hunt for signs such as unusual publication bursts, tarball differences, unexpected github: dependencies pinned to commit SHAs, and files present in published tarballs but absent from package allowlists.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Analysis of the incident found the attackers abused a GitHub Actions pull_request_target workflow pattern, cache poisoning, and OIDC token theft from runner memory to publish signed malicious packages under a trusted identity. The malware used npm lifecycle hooks and a staged payload to exfiltrate secrets and attempt self-propagation to additional packages.
On 2026-05-11, attackers compromised 42 @tanstack/* npm packages and published 84 malicious versions within six minutes through TanStack’s legitimate CI/CD pipeline. The malicious releases carried valid SLSA Build Level 3 provenance despite containing malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourcezeropath.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.