GHSA-g7cv-rxg3-hmpx
Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
Quick fix
GHSA-g7cv-rxg3-hmpx — @tanstack/arktype-adapter: upgrade to the fixed version with the command below.
npm install @tanstack/arktype-adapter@1.166.16Details
## Summary
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 `@tanstack/*` packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for `TanStack/router`, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a `pull_request_target` "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity.
Each affected package received exactly two malicious versions, published a few minutes apart.
## Impact
A user installing any affected version executes a payload (~2.3 MB obfuscated `router_init.js`) at install time that:
- Harvests credentials from common locations: - AWS instance metadata (IMDS) and Secrets Manager - GCP metadata service - Kubernetes service-account tokens - HashiCorp Vault tokens - `~/.npmrc` (npm tokens) - GitHub tokens (env vars, `gh` CLI config, `.git-credentials`) - SSH private keys (`~/.ssh/`) - Exfiltrates harvested data over the Session/Oxen messenger file-upload network (`filev2.getsession.org`, `seed{1,2,3}.getsession.org`). This is end-to-end encrypted with no attacker-controlled C2, so blocking by IP or domain is the only network mitigation. - Enumerates packages that the victim maintains via `registry.npmjs.org/-/v1/search?text=maintainer:<user>` and republishes them with the same injection, propagating the compromise across npm.
Any developer or CI environment that ran `npm install`, `pnpm install`, or `yarn install` against an affected version on 2026-05-11 should be considered compromised. All credentials accessible to the install process should be rotated immediately. Cloud audit logs should be reviewed for activity originating from the affected hosts during and after the install window.
## Detection
Inspect the published manifest of any pinned `@tanstack/*` version. Malicious manifests contain this exact `optionalDependencies` entry:
```json "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49eedf774dd4b0cfa308722bc463cfe5885c" } ```
To check a version without running install scripts:
```bash npm pack @tanstack/<name>@<version> # downloads tarball; does NOT execute lifecycle scripts tar -xzf *.tgz grep -A3 optionalDependencies package/package.json ls -la package/router_init.js # malicious payload, ~2.3 MB, present at package root ```
The payload file `router_init.js` is approximately 2.3 MB of obfuscated JavaScript. It is placed at the tarball root and is intentionally not declared in the package's `"files"` array, so it does not appear in the package's documented contents.
## Mechanism
`@tanstack/setup` is not a real package on the npm registry. The `github:tanstack/router#79ac49ee...` specifier resolves to an orphan commit pushed to a fork in the `tanstack/router` GitHub fork network. GitHub serves commits across the entire fork network for git-URL dependencies, so the attacker did not require write access to `TanStack/router` itself — only the ability to fork and push to their own fork.
When npm processes the optional dependency, it:
1. Fetches the orphan commit from the fork network. 2. Installs the commit's declared dependencies (which include a real `bun` binary). 3. Runs the commit's `prepare` lifecycle script: `bun run tanstack_runner.js && exit 1`. The trailing `exit 1` causes the optional install to fail, after which npm silently discards it — leaving no `node_modules` trace. 4. The `tanstack_runner.js` script in turn executes `router_init.js` from the host package's tarball.
## Patches
Affected versions are being deprecated on npm with a `SECURITY:` notice. Where npm policy allows (no existing third-party dependents), affected versions are also being unpublished. The npm security team has been engaged to pull tarballs server-side for versions that cannot be unpublished.
Clean follow-up releases are being prepared. Update to the patched version listed in the affected-products table for each package, then reinstall from a clean lockfile.
## Workarounds
Until clean follow-up releases are available:
- Pin every `@tanstack/*` dependency to a known-good version published before 2026-05-11 19:00 UTC. The last known-good version for most affected packages was published on 2026-03-15. - Delete `node_modules` and the lockfile, then reinstall to ensure no transitive dependency resolves to a malicious version. - Configure npm to skip lifecycle scripts on install (`npm config set ignore-scripts true`) as a temporary defense-in-depth measure. - For CI, audit any pipeline that ran `install` against `@tanstack/*` between 19:20 and 19:30 UTC on 2026-05-11. Treat the runner as compromised and rotate any secrets it had access to.
## Indicators of compromise
| Indicator | Value | |---|---| | Malicious git ref | `github:tanstack/router#79ac49eedf774dd4b0cfa308722bc463cfe5885c` | | Fictitious package name | `@tanstack/setup` | | Payload filename | `router_init.js` (~2.3 MB, package root, undeclared in `files`) | | Helper filename in orphan commit | `tanstack_runner.js` | | Exfiltration network | `filev2.getsession.org`, `seed1.getsession.org`, `seed2.getsession.org`, `seed3.getsession.org` | | Second-stage payload URLs | `https://litter.catbox.moe/h8nc9u.js`, `https://litter.catbox.moe/7rrc6l.mjs` | | Poisoned cache key | `Linux-pnpm-store-6f9233a50def742c09fde54f56553d6b449a535adf87d4083690539f49ae4da11` | | Publish window (UTC) | 2026-05-11 19:20 — 19:26 | | Publish mechanism | GitHub Actions OIDC trusted publisher (`oidc:db7d6f54-05d5-412b-8a10-e7a8398b303e`) | | Workflow runs | https://github.com/TanStack/router/actions/runs/25613093674 (attempt 4), https://github.com/TanStack/router/actions/runs/25691781302 | | Attacker GitHub accounts | `zblgg` (id 127806521), `voicproducoes` (id 269549300) | | Attacker fork (renamed to evade detection) | https://github.com/zblgg/configuration |
## Credits
- The security researcher who initially disclosed the vulnerability publicly with detailed analysis at https://github.com/TanStack/router/issues/7383
## References
- Public incident tracking issue: https://github.com/TanStack/router/issues/7383 - Related research: - Adnan Khan, "The Monsters in Your Build Cache: GitHub Actions Cache Poisoning" (May 2024) - GitHub Security Lab, "Keeping your GitHub Actions and workflows secure: Preventing Pwn Requests" - StepSecurity, "tj-actions/changed-files action is compromised" (March 2025) — the malicious payload reuses this incident's runner-memory extraction technique verbatim
Are you affected?
Enter the version of the package you're using.
Affected packages
1.166.12Fixed in: 1.166.16npm install @tanstack/arktype-adapter@1.166.161.161.9Fixed in: 1.161.13npm install @tanstack/eslint-plugin-router@1.161.130.0.4Fixed in: 0.0.8npm install @tanstack/eslint-plugin-start@0.0.81.161.9Fixed in: 1.161.13npm install @tanstack/history@1.161.131.154.12Fixed in: 1.154.16npm install @tanstack/nitro-v2-vite-plugin@1.154.161.169.5Fixed in: 1.169.9npm install @tanstack/react-router@1.169.91.166.16Fixed in: 1.166.20npm install @tanstack/react-router-devtools@1.166.201.166.15Fixed in: 1.166.19npm install @tanstack/react-router-ssr-query@1.166.191.167.68Fixed in: 1.167.72npm install @tanstack/react-start@1.167.721.166.51Fixed in: 1.166.55npm install @tanstack/react-start-client@1.166.550.0.47Fixed in: 0.0.51npm install @tanstack/react-start-rsc@0.0.511.166.55Fixed in: 1.166.59npm install @tanstack/react-start-server@1.166.591.166.46Fixed in: 1.166.50npm install @tanstack/router-cli@1.166.501.169.5Fixed in: 1.169.9npm install @tanstack/router-core@1.169.91.166.16Fixed in: 1.166.20npm install @tanstack/router-devtools@1.166.201.167.6Fixed in: 1.167.10npm install @tanstack/router-devtools-core@1.167.101.166.45Fixed in: 1.166.49npm install @tanstack/router-generator@1.166.491.167.38Fixed in: 1.167.42npm install @tanstack/router-plugin@1.167.421.168.3Fixed in: 1.168.7npm install @tanstack/router-ssr-query-core@1.168.71.161.11Fixed in: 1.161.15npm install @tanstack/router-utils@1.161.151.166.53Fixed in: 1.166.57npm install @tanstack/router-vite-plugin@1.166.571.169.5Fixed in: 1.169.9npm install @tanstack/solid-router@1.169.91.166.16Fixed in: 1.166.20npm install @tanstack/solid-router-devtools@1.166.201.166.15Fixed in: 1.166.19npm install @tanstack/solid-router-ssr-query@1.166.191.167.65Fixed in: 1.167.69npm install @tanstack/solid-start@1.167.691.166.50Fixed in: 1.166.54npm install @tanstack/solid-start-client@1.166.541.166.54Fixed in: 1.166.58npm install @tanstack/solid-start-server@1.166.581.168.5Fixed in: 1.168.9npm install @tanstack/start-client-core@1.168.91.161.9Fixed in: 1.161.13npm install @tanstack/start-fn-stubs@1.161.131.169.23Fixed in: 1.169.27npm install @tanstack/start-plugin-core@1.169.271.167.33Fixed in: 1.167.37npm install @tanstack/start-server-core@1.167.371.166.44Fixed in: 1.166.48npm install @tanstack/start-static-server-functions@1.166.481.166.38Fixed in: 1.166.42npm install @tanstack/start-storage-context@1.166.421.166.12Fixed in: 1.166.16npm install @tanstack/valibot-adapter@1.166.161.161.10Fixed in: 1.161.14npm install @tanstack/virtual-file-routes@1.161.141.169.5Fixed in: 1.169.9npm install @tanstack/vue-router@1.169.91.166.16Fixed in: 1.166.20npm install @tanstack/vue-router-devtools@1.166.201.166.15Fixed in: 1.166.19npm install @tanstack/vue-router-ssr-query@1.166.191.167.61Fixed in: 1.167.65npm install @tanstack/vue-start@1.167.651.166.46Fixed in: 1.166.50npm install @tanstack/vue-start-client@1.166.501.166.50Fixed in: 1.166.54npm install @tanstack/vue-start-server@1.166.541.166.12Fixed in: 1.166.16npm install @tanstack/zod-adapter@1.166.161.166.15Fixed in: 1.166.16npm install @tanstack/arktype-adapter@1.166.161.161.12Fixed in: 1.161.13npm install @tanstack/eslint-plugin-router@1.161.130.0.7Fixed in: 0.0.8npm install @tanstack/eslint-plugin-start@0.0.81.161.12Fixed in: 1.161.13npm install @tanstack/history@1.161.131.154.15Fixed in: 1.154.16npm install @tanstack/nitro-v2-vite-plugin@1.154.161.169.8Fixed in: 1.169.9npm install @tanstack/react-router@1.169.91.166.19Fixed in: 1.166.20npm install @tanstack/react-router-devtools@1.166.201.166.18Fixed in: 1.166.19npm install @tanstack/react-router-ssr-query@1.166.191.167.71Fixed in: 1.167.72npm install @tanstack/react-start@1.167.721.166.54Fixed in: 1.166.55npm install @tanstack/react-start-client@1.166.550.0.50Fixed in: 0.0.51npm install @tanstack/react-start-rsc@0.0.511.166.58Fixed in: 1.166.59npm install @tanstack/react-start-server@1.166.591.166.49Fixed in: 1.166.50npm install @tanstack/router-cli@1.166.501.169.8Fixed in: 1.169.9npm install @tanstack/router-core@1.169.91.166.19Fixed in: 1.166.20npm install @tanstack/router-devtools@1.166.201.167.9Fixed in: 1.167.10npm install @tanstack/router-devtools-core@1.167.101.166.48Fixed in: 1.166.49npm install @tanstack/router-generator@1.166.491.167.41Fixed in: 1.167.42npm install @tanstack/router-plugin@1.167.421.168.6Fixed in: 1.168.7npm install @tanstack/router-ssr-query-core@1.168.71.161.14Fixed in: 1.161.15npm install @tanstack/router-utils@1.161.151.166.56Fixed in: 1.166.57npm install @tanstack/router-vite-plugin@1.166.571.169.8Fixed in: 1.169.9npm install @tanstack/solid-router@1.169.91.166.19Fixed in: 1.166.20npm install @tanstack/solid-router-devtools@1.166.201.166.18Fixed in: 1.166.19npm install @tanstack/solid-router-ssr-query@1.166.191.167.68Fixed in: 1.167.69npm install @tanstack/solid-start@1.167.691.166.53Fixed in: 1.166.54npm install @tanstack/solid-start-client@1.166.541.166.57Fixed in: 1.166.58npm install @tanstack/solid-start-server@1.166.581.168.8Fixed in: 1.168.9npm install @tanstack/start-client-core@1.168.91.161.12Fixed in: 1.161.13npm install @tanstack/start-fn-stubs@1.161.131.169.26Fixed in: 1.169.27npm install @tanstack/start-plugin-core@1.169.271.167.36Fixed in: 1.167.37npm install @tanstack/start-server-core@1.167.371.166.47Fixed in: 1.166.48npm install @tanstack/start-static-server-functions@1.166.481.166.41Fixed in: 1.166.42npm install @tanstack/start-storage-context@1.166.421.166.15Fixed in: 1.166.16npm install @tanstack/valibot-adapter@1.166.161.161.13Fixed in: 1.161.14npm install @tanstack/virtual-file-routes@1.161.141.169.8Fixed in: 1.169.9npm install @tanstack/vue-router@1.169.91.166.19Fixed in: 1.166.20npm install @tanstack/vue-router-devtools@1.166.201.166.18Fixed in: 1.166.19npm install @tanstack/vue-router-ssr-query@1.166.191.167.64Fixed in: 1.167.65npm install @tanstack/vue-start@1.167.651.166.49Fixed in: 1.166.50npm install @tanstack/vue-start-client@1.166.501.166.53Fixed in: 1.166.54npm install @tanstack/vue-start-server@1.166.541.166.15Fixed in: 1.166.16npm install @tanstack/zod-adapter@1.166.16References
- https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-45321[ADVISORY]
- https://github.com/TanStack/router/issues/7383[WEB]
- https://github.com/TanStack/router[PACKAGE]
- https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack[WEB]
- https://tanstack.com/blog/npm-supply-chain-compromise-postmortem[WEB]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45321[WEB]
- https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem[WEB]