Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
Blog post from Socket
A supply-chain attack has been identified targeting the unscoped "tanstack" package on npm, a deceptive imitation of the legitimate @tanstack/* organization. This attack, discovered by the Socket Research Team, involves the package's maintainer, sh20raj, releasing malicious versions that exfiltrate environment variable files from developers' machines to an attacker-controlled endpoint. The affected versions, 2.0.4 through 2.0.7, were published rapidly and share a common exfiltration infrastructure, indicating a premeditated attack rather than a gradual compromise. The attack is part of a broader brandjacking effort involving the TanStack name, as confirmed by Tanner Linsley, creator of TanStack, who states that the package is unrelated to the official TanStack projects and is involved in a trademark infringement dispute. Users who installed these versions are advised to uninstall them, rotate their secrets, audit dependencies, and monitor for suspicious activities, as the attack leverages a Svix source for exfiltration, making it difficult for defenders to track what has been compromised.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 2 | 1,821 | 338 | 111 | +22% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.