CVE-2026-45321
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
Description
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.
In plain language
AI Act nowMalicious code was added to specific versions of several @tanstack/* packages to steal your cloud passwords, GitHub access tokens, and SSH keys when you install them; if you use these packages, you should treat this as an urgent supply-chain compromise and update now.
CVE-2026-45321 covers a supply-chain compromise of multiple @tanstack/* packages, where attackers published credential-stealing malware under a trusted GitHub Actions identity by chaining a workflow misconfiguration, cache poisoning, and runtime memory extraction of the Actions OIDC token; exploitation is confirmed via CISA KEV (used in ransomware campaigns).
What to do now
- Check your project dependencies to see whether any of these packages are installed at versions listed in TanStack’s advisory for CVE-2026-45321.
- Stop using/building any affected app or CI workflow until you’ve updated dependencies.
- Upgrade/replace the affected @tanstack/* packages to the versions recommended in the TanStack security advisory GHSA-g7cv-rxg3-hmpx.
- Rotate any credentials that might have been accessible during install/build (cloud keys, GitHub tokens, SSH keys) and revoke tokens that were used.
- Review your CI/CD logs and npm install/build logs for unexpected scripts/actions triggered by these packages.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
References
- CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositoriesen·The Hacker News· Exploited TanStack supply-chain
- Охота на эксплойты: зачем и как это делать специалистам по ИБru·Хабр — Информационная безопасность· Research
- TeamPCP Supply Chain Campaign: Activity Through 2026-06-07en·SANS Internet Storm Center· Exploited TeamPCP-linked tooling TeamPCP
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-45321 and every CVE in our database. Create a free account — no credit card required.
Create Free Account