CVE Tools

CVE-2026-45321

Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys

Published: May 12, 2026Updated: May 29, 2026 Sources: CVE List NVD BDUCWE-506

Description

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.

In plain language

AI Act now

Malicious code was added to specific versions of several @tanstack/* packages to steal your cloud passwords, GitHub access tokens, and SSH keys when you install them; if you use these packages, you should treat this as an urgent supply-chain compromise and update now.

Executive summary

CVE-2026-45321 covers a supply-chain compromise of multiple @tanstack/* packages, where attackers published credential-stealing malware under a trusted GitHub Actions identity by chaining a workflow misconfiguration, cache poisoning, and runtime memory extraction of the Actions OIDC token; exploitation is confirmed via CISA KEV (used in ransomware campaigns).

If affected, business impact
Cloud credentials theftGitHub token compromiseSSH key exfiltrationFull development environment takeover

What to do now

  1. Check your project dependencies to see whether any of these packages are installed at versions listed in TanStack’s advisory for CVE-2026-45321.
  2. Stop using/building any affected app or CI workflow until you’ve updated dependencies.
  3. Upgrade/replace the affected @tanstack/* packages to the versions recommended in the TanStack security advisory GHSA-g7cv-rxg3-hmpx.
  4. Rotate any credentials that might have been accessible during install/build (cloud keys, GitHub tokens, SSH keys) and revoke tokens that were used.
  5. Review your CI/CD logs and npm install/build logs for unexpected scripts/actions triggered by these packages.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:RS:CC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 207 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:May 27, 2026
Remediation due:Jun 10, 2026
Ransomware:Known ransomware use

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Official Patch Available
Workaround Available

References

and 5 more references View all →
3

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-45321 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store