The TanStack npm Supply Chain Attack

Updated 5 Oct 2026 · Incident date 11 May 2026 · npm

Package@tanstack/* - 84 malicious versions across 42 packages published 19:20-19:26 UTC (same wave hit Mistral AI, UiPath, OpenSearch, Guardrails AI)
Filerouter_init.js

On 11 May 2026, attackers published 84 malicious versions across 42 @tanstack npm packages, including @tanstack/react-router 1.169.5 and 1.169.8. Each bad version carried a new hidden file, router_init.js, that ran at install time and stole build secrets.

The same campaign, called Mini Shai-Hulud, also hit packages from Mistral AI, UiPath, OpenSearch and Guardrails AI. TanStack declared its repository and every currently published version safe after a three-day sweep.

What happened

An attacker used three chained flaws in the TanStack GitHub Actions setup to publish poisoned packages straight to npm. The TanStack postmortem describes each step.

  1. The attacker forked the repository as zblgg/configuration and opened a pull request. A pull_request_target workflow ran the fork's build code without an approval gate.
  2. That code wrote a poisoned 1.1 GB pnpm store entry into the shared GitHub Actions cache. A later production workflow on the main branch restored it.
  3. Malicious binaries in the cache read the memory of the runner process, took the OIDC token and posted it directly to registry.npmjs.org. This skipped the official publish step.

The first batch of 42 packages went live at 19:20 UTC on 11 May. A second batch followed at 19:26 UTC. An outside researcher opened an issue at 19:46 UTC. TanStack began deprecating versions at 20:19 UTC and deprecated all 84 by 21:03 UTC. npm removed the tarballs between 22:13 and 23:55 UTC.

The poisoned tarballs gained a file that the clean earlier versions did not have. router_init.js is about 2.3 MB, is obfuscated, and sits in the package root outside the declared files field. A new optionalDependencies entry pulled a payload from a git commit in the attacker's fork. Snyk reports that a prepare hook ran a file named tanstack_runner.js.

The payload collected credentials and sent them out. The postmortem lists AWS, GCP and Kubernetes tokens, Vault tokens, ~/.npmrc, GitHub tokens and SSH keys. It also spread to other packages that the stolen npm credentials can publish. Wiz reports that the malware installed a gh-token-monitor daemon. It polls GitHub every 60 seconds and runs rm -rf ~/ when the stolen token is revoked.

Affected versions

Two versions of each of 42 packages in the @tanstack scope are affected, 84 versions in total. TanStack lists the exact versions in advisory GHSA-g7cv-rxg3-hmpx. Snyk lists these examples.

PackageBad versions
@tanstack/react-router1.169.5, 1.169.8
@tanstack/vue-router1.169.5, 1.169.8
@tanstack/solid-router1.169.5, 1.169.8
@tanstack/router-core1.169.5, 1.169.8
@tanstack/react-start1.167.68, 1.167.71
@tanstack/router-plugin1.167.38, 1.167.41

The postmortem also names @tanstack/history 1.161.9 and 1.161.12. These families were not affected: query, table, form, virtual, store and the @tanstack/start meta-package.

Wiz counts more than 120 npm packages across several namespaces, plus two PyPI packages, guardrails-ai 0.10.1 and mistralai 2.4.6.

Indicators of compromise

These indicators come from the TanStack, Wiz and Snyk reports.

How to check

Search your project for the payload file and the git dependency. Run these commands in the project folder. They only read files.

find . -name router_init.js -exec shasum -a 256 {} +
grep -rl "79ac49eedf774dd4b0cfa308722bc463cfe5885c" node_modules package-lock.json pnpm-lock.yaml

Check for the persistence files and the daemon.

ls .claude/router_runtime.js .claude/setup.mjs .vscode/setup.mjs ~/.local/bin/gh-token-monitor.sh ~/Library/LaunchAgents/com.user.gh-token-monitor.plist

Also read your lockfile and CI logs for the bad versions in the table above. A match on any command means the machine or runner ran the payload.

What to do now

  1. Stop the gh-token-monitor daemon and remove its files before you revoke any token. Wiz and Snyk both report that a revoked token triggers deletion of the home directory.
  2. Remove the .claude and .vscode persistence files and revert any malicious commits.
  3. Rotate GitHub, npm, AWS, GCP, Vault, Kubernetes and SSH credentials that the machine or runner can read.
  4. Pin to a clean version. TanStack states that every currently published version is safe to install.
  5. Block *.getsession.org and git-tanstack.com at the DNS or proxy level.
  6. Purge GitHub Actions caches, pin actions to commit SHAs and restrict OIDC trusted publishing to a named workflow and branch. Snyk also suggests a package manager release-age delay of 7 days.

Vigilance compares the version you trust with a new one and reports the file that gained a new capability. For this attack, that file is router_init.js. See the full attack list and download Vigilance.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old @tanstack/-prev --new @tanstack/-current
files scanned: 70 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   router_init.js
           It runs a command on its own when it is installed, reads saved passwords and access keys and runs a hidden, encoded command.

Frequently asked questions

What was the TanStack npm supply chain attack?

On 11 May 2026 attackers published 84 malicious versions across 42 @tanstack npm packages. Each carried a hidden file, router_init.js, that ran at install time and stole build secrets and cloud credentials.

How do I check if I installed a compromised TanStack package?

Search your project and lockfiles for router_init.js, for the git dependency github:tanstack/router#79ac49eedf774dd4b0cfa308722bc463cfe5885c, and for the bad versions such as @tanstack/react-router 1.169.5 and 1.169.8.

Is it safe to install TanStack now?

TanStack states that every currently published version of every TanStack package is safe to install. The 84 malicious versions were deprecated and later removed from npm.

Sources

  1. tanstack.com/blog/npm-supply-chain-compromise-postmortem
  2. wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised
  3. snyk.io/blog/tanstack-npm-packages-compromised/

More supply chain attacks

All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free