Home / Companies / Cloudsmith / Blog / Post Details
Content Deep Dive

TanStack npm Packages Compromised in Supply-Chain Attack

Blog post from Cloudsmith

Post Details
Company
Date Published
Author
Nigel Douglas
Word Count
502
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket's threat research team has discovered a significant supply chain attack involving over 84 malicious TanStack npm package artifacts across 42 packages, including the widely-used @tanstack/react-router, which has over 12 million weekly downloads. Attributed to TeamPCP's "Mini Shai-Hulud" attack, the self-propagating malware exploits CI/CD secrets in a manner common to other supply chain attacks. Although these compromised packages were quickly identified after publication, concerns remain about whether organizations inadvertently used them before they were removed from the npm registry. To combat such threats, users can implement safeguards like Cloudsmith's automated cooldown policies, which enforce a time lag on new package consumption, and monitor advisories like OSV's MAL-2026-3463. The attack involved exploiting vulnerabilities in GitHub Actions, including cache poisoning and token extraction, and highlights the need for robust supply chain security measures as similar attacks are expected to continue.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 1 2,324 403 114 +18%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.