The TanStack npm Supply Chain Attack
Updated 5 Oct 2026 · Incident date 11 May 2026 · npm
@tanstack/* - 84 malicious versions across 42 packages published 19:20-19:26 UTC (same wave hit Mistral AI, UiPath, OpenSearch, Guardrails AI)router_init.jsOn 11 May 2026, attackers published 84 malicious versions across 42 @tanstack npm packages, including @tanstack/react-router 1.169.5 and 1.169.8. Each bad version carried a new hidden file, router_init.js, that ran at install time and stole build secrets.
The same campaign, called Mini Shai-Hulud, also hit packages from Mistral AI, UiPath, OpenSearch and Guardrails AI. TanStack declared its repository and every currently published version safe after a three-day sweep.
What happened
An attacker used three chained flaws in the TanStack GitHub Actions setup to publish poisoned packages straight to npm. The TanStack postmortem describes each step.
- The attacker forked the repository as
zblgg/configurationand opened a pull request. Apull_request_targetworkflow ran the fork's build code without an approval gate. - That code wrote a poisoned 1.1 GB pnpm store entry into the shared GitHub Actions cache. A later production workflow on the main branch restored it.
- Malicious binaries in the cache read the memory of the runner process, took the OIDC token and posted it directly to
registry.npmjs.org. This skipped the official publish step.
The first batch of 42 packages went live at 19:20 UTC on 11 May. A second batch followed at 19:26 UTC. An outside researcher opened an issue at 19:46 UTC. TanStack began deprecating versions at 20:19 UTC and deprecated all 84 by 21:03 UTC. npm removed the tarballs between 22:13 and 23:55 UTC.
The poisoned tarballs gained a file that the clean earlier versions did not have. router_init.js is about 2.3 MB, is obfuscated, and sits in the package root outside the declared files field. A new optionalDependencies entry pulled a payload from a git commit in the attacker's fork. Snyk reports that a prepare hook ran a file named tanstack_runner.js.
The payload collected credentials and sent them out. The postmortem lists AWS, GCP and Kubernetes tokens, Vault tokens, ~/.npmrc, GitHub tokens and SSH keys. It also spread to other packages that the stolen npm credentials can publish. Wiz reports that the malware installed a gh-token-monitor daemon. It polls GitHub every 60 seconds and runs rm -rf ~/ when the stolen token is revoked.
Affected versions
Two versions of each of 42 packages in the @tanstack scope are affected, 84 versions in total. TanStack lists the exact versions in advisory GHSA-g7cv-rxg3-hmpx. Snyk lists these examples.
| Package | Bad versions |
|---|---|
@tanstack/react-router | 1.169.5, 1.169.8 |
@tanstack/vue-router | 1.169.5, 1.169.8 |
@tanstack/solid-router | 1.169.5, 1.169.8 |
@tanstack/router-core | 1.169.5, 1.169.8 |
@tanstack/react-start | 1.167.68, 1.167.71 |
@tanstack/router-plugin | 1.167.38, 1.167.41 |
The postmortem also names @tanstack/history 1.161.9 and 1.161.12. These families were not affected: query, table, form, virtual, store and the @tanstack/start meta-package.
Wiz counts more than 120 npm packages across several namespaces, plus two PyPI packages, guardrails-ai 0.10.1 and mistralai 2.4.6.
Indicators of compromise
These indicators come from the TanStack, Wiz and Snyk reports.
- File
router_init.jsin the package root, SHA-256ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c - File
tanstack_runner.js, SHA-2562ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96 - Dependency
"@tanstack/setup": "github:tanstack/router#79ac49eedf774dd4b0cfa308722bc463cfe5885c"inoptionalDependencies - Domains
filev2.getsession.org,seed1.getsession.org,seed2.getsession.org,seed3.getsession.organdgit-tanstack.com - Download URLs
litter.catbox.moe/h8nc9u.jsandlitter.catbox.moe/7rrc6l.mjs - Persistence files
.claude/router_runtime.js,.claude/settings.json,.claude/setup.mjs,.vscode/setup.mjsand.vscode/tasks.json - Daemon
gh-token-monitor:~/.local/bin/gh-token-monitor.shand a systemd user service on Linux, or~/Library/LaunchAgents/com.user.gh-token-monitor.pliston macOS - Git commits authored as
claude@users.noreply.github.com - Advisory GHSA-g7cv-rxg3-hmpx and CVE-2026-45321 (as listed by Snyk)
How to check
Search your project for the payload file and the git dependency. Run these commands in the project folder. They only read files.
find . -name router_init.js -exec shasum -a 256 {} +grep -rl "79ac49eedf774dd4b0cfa308722bc463cfe5885c" node_modules package-lock.json pnpm-lock.yaml
Check for the persistence files and the daemon.
ls .claude/router_runtime.js .claude/setup.mjs .vscode/setup.mjs ~/.local/bin/gh-token-monitor.sh ~/Library/LaunchAgents/com.user.gh-token-monitor.plist
Also read your lockfile and CI logs for the bad versions in the table above. A match on any command means the machine or runner ran the payload.
What to do now
- Stop the
gh-token-monitordaemon and remove its files before you revoke any token. Wiz and Snyk both report that a revoked token triggers deletion of the home directory. - Remove the
.claudeand.vscodepersistence files and revert any malicious commits. - Rotate GitHub, npm, AWS, GCP, Vault, Kubernetes and SSH credentials that the machine or runner can read.
- Pin to a clean version. TanStack states that every currently published version is safe to install.
- Block
*.getsession.organdgit-tanstack.comat the DNS or proxy level. - Purge GitHub Actions caches, pin actions to commit SHAs and restrict OIDC trusted publishing to a named workflow and branch. Snyk also suggests a package manager release-age delay of 7 days.
Vigilance compares the version you trust with a new one and reports the file that gained a new capability. For this attack, that file is router_init.js. See the full attack list and download Vigilance.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 70 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE router_init.js It runs a command on its own when it is installed, reads saved passwords and access keys and runs a hidden, encoded command.
Frequently asked questions
What was the TanStack npm supply chain attack?
On 11 May 2026 attackers published 84 malicious versions across 42 @tanstack npm packages. Each carried a hidden file, router_init.js, that ran at install time and stole build secrets and cloud credentials.
How do I check if I installed a compromised TanStack package?
Search your project and lockfiles for router_init.js, for the git dependency github:tanstack/router#79ac49eedf774dd4b0cfa308722bc463cfe5885c, and for the bad versions such as @tanstack/react-router 1.169.5 and 1.169.8.
Is it safe to install TanStack now?
TanStack states that every currently published version of every TanStack package is safe to install. The 84 malicious versions were deprecated and later removed from npm.
Sources
More supply chain attacks
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- Mastra AI npm compromise (Sapphire Sleet) 17 Jun 2026
- axios npm maintainer account takeover 31 Mar 2026
All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.