Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators TanStack npm Packages Compromised in Ongoing Supply-Chain Attack

79ac49eedf774dd4b0cfa308722bc463cfe5885c

TLP:CLEAR
Active

SHA-1 Hash

Description

Socket detected 84 compromised TanStack npm package artifacts modified with credential-stealing malware targeting CI systems, including GitHub Actions. Affected packages like @tanstack/react-router have over 12 million weekly downloads. The malicious versions contain router_init.js, a heavily obfuscated file with daemonization capabilities and environment variable access for GitHub Actions secrets. The compromise exploited GitHub Actions cache poisoning and pull_request_target patterns to extract OIDC tokens and authenticate malicious npm publishes through trusted-publisher bindings. The malware harvests credentials from GitHub Actions, AWS (IMDS, Secrets Manager, SSM), HashiCorp Vault, and Kubernetes, while establishing persistence in Claude Code and VS Code directories. Exfiltration occurs through Session's decentralized P2P network. The campaign includes self-propagation mechanisms that steal npm OIDC tokens and autonomously republish compromised packages. Updates indicate expansion...

Sightings (0)

No sightings recorded yet

Details

Name / Label
TanStack npm Packages Compromised in Ongoing Supply-Chain Attack
Pattern Type
STIX
Confidence
75%
Valid From
May 14, 2026 23:09
Total Sightings
0
Added
May 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 79ac49eedf774dd4b0cfa308722bc463cfe5885c

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.