Back Gigazine The popular JavaScript library suite 'TanStack,' which is downloaded millions of times every ...
A supply chain attack was carried out against TanStack, a set of libraries widely used in JavaScript and React development, by releasing malware-infused versions of its npm packages. According to TanStack's official post-incident report, on May 11, 2026, the attackers released versions containing a total of 84 malicious code snippets across 42 TanStack-related packages. Postmortem: TanStack npm supply-chain compromise | TanStack Blog
TanStack has officially deprecated the problematic version and requested npm to remove it. They have also implemented preventative measures, such as clearing the GitHub Actions cache and reviewing workflow settings. StepSecurity recommends that developers check their project's lock files, such as package-lock.json, pnpm-lock.yaml, and yarn.lock, for any problematic TanStack-related packages. If 'router_init.js' or '@tanstack/setup' are present in node_modules, it may indicate that a version containing malicious code has been installed. If you suspect you've installed a problematic version, simply updating the package isn't enough. TanStack officially advises treating affected environments as compromised and urging users to rotate their credentials for GitHub, npm, AWS, GCP, SSH, and other services. If a problematic version was installed in your CI environment, you'll also need to reissue any secrets stored in your CI environment. StepSecurity points out that if the distribution channels of popular libraries are exploited, there is a risk that authentication information could be stolen through normal package installation. They also recommend that when judging the security of an npm package, one should check not only the publisher's reputation, but also the contents of the lock file, whether it is a suspicious version released recently, and the permission management in the CI/CD settings.
May 12, 2026 16:20:00 in Security , Posted by log1d_ts
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
