CVE-2026-45321 tracks a supply-chain compromise affecting TanStack npm packages. An attacker chained an unsafe GitHub Actions pull_request_target workflow that executed fork-controlled code in a privileged repository context, poisoning of a shared GitHub Actions dependency cache across the fork-to-base trust boundary, and extraction of an OIDC token from the Actions runner process. The stolen token enabled publication through TanStack’s legitimate trusted-publisher identity. Eighty-four malicious releases across 42 packages were published with valid provenance attestations and contained credential-stealing malware.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (10 hidden).
This repository is a small educational lab that simulates an npm supply-chain attack associated with CVE-2026-45321/TanStack-themed compromise scenarios. It is not a full offensive toolkit; instead, it demonstrates how a malicious package can achieve install-time code execution through the npm `postinstall` lifecycle hook and how similar behavior could affect CI/CD pipelines. Repository structure: `attacker-package/` contains the core exploit logic, including `package.json` and `payload.js`; `fake-repo/` contains a GitHub Actions workflow simulation (`test.yml`) showing how CI could invoke installation of the malicious package; `victim-project/` is a placeholder directory representing the victim environment. The main exploit capability resides in `attacker-package/package.json`, which defines `postinstall: node payload.js`, causing `payload.js` to run automatically when the package is installed. The payload itself is simple but functional: it imports Node's `os` and `fs` modules, prints a marker string indicating execution, collects `USER`, hostname, and platform information, and writes that data to `loot.txt`. There is no network exfiltration, persistence, privilege escalation, or remote command-and-control in the provided code. As such, the exploit is operational as a local proof of install-time execution, but the payload is basic and hardcoded. The CI/CD simulation in `fake-repo/test.yml` uses a `pull_request_target` workflow and demonstrates how an install step could execute attacker-controlled package code on a GitHub Actions runner. This reinforces the repository's purpose as a supply-chain and CI/CD abuse demonstration rather than a stealthy real-world malware sample.
This repository is a small educational proof-of-concept simulating an npm supply-chain compromise associated with CVE-2026-45321 and a TanStack-themed package name. The repo contains 5 files: a README, a GitHub Actions workflow snippet (`download (2)`), an npm lockfile-like JSON (`download (7)`), a package manifest mislabeled as `payload.js`, and a JavaScript payload mislabeled as `tanstack-react-router-1.169.5.tgz`. Despite the filename/content mismatch, the intended structure is clear from the README. Core exploit behavior: the malicious package impersonates `@tanstack/react-router` version `1.169.5` and defines a `postinstall` script (`node payload.js`). When the victim installs the tarball, npm executes the lifecycle hook automatically. The payload then collects simple host metadata (`USER`, hostname, platform), prints a marker string (`=== MALICIOUS PAYLOAD EXECUTED ===`), and writes the data to `loot.txt`. This demonstrates install-time arbitrary code execution rather than remote exploitation. The repository does not contain a full offensive framework and is not a detection script. It is an operational PoC because it includes a working payload, though the payload is basic and hardcoded. The main attack vectors are supply-chain compromise of a dependency, CI/CD execution through GitHub Actions `pull_request_target` workflows that run `npm install`, and local file-based package installation via a tarball path. No external C2, exfiltration endpoint, or network beaconing is present in the code; all observable actions are local file writes and console output. Notable endpoints and artifacts include the local tarball path `../attacker-package/tanstack-react-router-1.169.5.tgz`, the output file `loot.txt`, the lifecycle command `node payload.js`, and references to GitHub, NVD, npm, and GitHub Actions documentation. Overall, the repository’s purpose is to demonstrate how a malicious npm package can abuse lifecycle hooks to gain code execution during dependency installation, especially in developer or CI environments that implicitly trust package installs.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
50 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A TanStack npm supply-chain compromise affecting the Router and Start ecosystem. Attackers abused an unsafe pull_request_target workflow, GitHub Actions cache poisoning, and OIDC-token extraction to publish malicious package releases containing an obfuscated install-time credential-stealing payload.
A TanStack npm supply-chain compromise in which attackers abused a GitHub Actions workflow/cache-poisoning chain and extracted an OpenID Connect token to publish malicious releases of TanStack packages. The install-time payload harvested developer and cloud credentials, enabling downstream account compromise and private-source-code theft.
A TanStack npm-package supply-chain compromise in which 84 malicious releases across 42 packages executed credential-stealing code on developer machines. The stolen credentials included GitHub OAuth tokens, SSH keys, and cloud credentials, enabling unauthorized access to private source-code repositories at CrowdSec and affecting developer devices at other organizations.
A CVE explicitly associated with the TeamPCP software supply chain campaign, but the content provides no technical details about the flaw itself.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.