Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
914
Company Posts That Month
32
Language
English
Hacker News Points
-
Post removed?
No
Summary

A supply-chain attack has been identified targeting the unscoped "tanstack" package on npm, a deceptive imitation of the legitimate @tanstack/* organization. This attack, discovered by the Socket Research Team, involves the package's maintainer, sh20raj, releasing malicious versions that exfiltrate environment variable files from developers' machines to an attacker-controlled endpoint. The affected versions, 2.0.4 through 2.0.7, were published rapidly and share a common exfiltration infrastructure, indicating a premeditated attack rather than a gradual compromise. The attack is part of a broader brandjacking effort involving the TanStack name, as confirmed by Tanner Linsley, creator of TanStack, who states that the package is unrelated to the official TanStack projects and is involved in a trademark infringement dispute. Users who installed these versions are advised to uninstall them, rotate their secrets, audit dependencies, and monitor for suspicious activities, as the attack leverages a Svix source for exfiltration, making it difficult for defenders to track what has been compromised.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 2 1,821 338 111 +22%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.