The frontend ecosystem has been hit by a rare npm supply chain attack. In a post-mortem, TanStack confirmed that an attacker pushed 42 @tanstack/* packages — 84 malicious versions total — through the official release pipeline between 3:20 and 3:26 a.m. UTC+8 on May 12. Affected packages include commonly used frontend dependencies like @tanstack/react-router, @tanstack/react-start, and @tanstack/router-core. GitHub Advisory marked the vulnerability as Critical with a CVSS score of 9.6.
What makes this attack so dangerous is how legitimate the malicious packages looked. TanStack says the attacker didn't steal npm tokens or directly modify the release workflow. Instead, they exploited pull_request_target configuration risks, GitHub Actions cache poisoning, and runtime OIDC token extraction to inject malicious code into the release environment. Although the normal build steps failed, the malicious code still used a trusted publisher identity to push directly to npm.
Security firm StepSecurity noted that the malicious packages also carried valid SLSA provenance (build source attestation). This proves that a signature only confirms a package came from a particular pipeline — it doesn't mean the pipeline itself wasn't compromised. For developers, relying solely on provenance badges or npm trusted publisher status is no longer enough; CI/CD pipelines themselves must be audited as an attack surface.
The compromised versions are easy to identify: package.json contains an extra optionalDependencies entry for @tanstack/setup pointing to github:tanstack/router#79ac49ee..., and the root directory includes a roughly 2.3 MB obfuscated file called router_init.js. Upon installation, the script steals AWS, GCP, Kubernetes, Vault, GitHub tokens, .npmrc credentials, and SSH private keys, exfiltrating them over the Session/Oxen network.
StepSecurity also reported that the malicious code has self-propagation capabilities — it enumerates other npm packages under the victim maintainer's name and attempts to poison them as well. Some samples include persistence mechanisms and destructive cleanup logic triggered by token revocation. TanStack has deprecated the affected versions and contacted npm security to remove the malicious tarballs. The official recommendation: any machine that installed an affected @tanstack/* package between 3:20 and 3:30 a.m. UTC+8 on May 12 should be treated as compromised. Immediately rotate credentials for cloud services, GitHub, npm, and SSH, and reinstall safe versions from a clean lockfile.