METABYTE
Back to articles

TanStack NPM Packages Compromised: A Supply Chain Attack

Someone treated open-source like an all-you-can-eat buffet and served malicious code in TanStack packages.

11 mai 20261 min read
TanStack NPM Packages Compromised: A Supply Chain Attack

Remember that feeling when you run npm install and hope nothing blows up? This time hope wasn't enough: several TanStack packages (including TanStack Router) have been compromised.

According to the GitHub issue, attackers gained access to NPM accounts and published malicious versions. As usual, users noticed something was off when their builds started acting suspiciously — like your CI/CD pipeline decided to throw a party without your permission.

What happened?

  • NPM accounts associated with TanStack were compromised.
  • Malicious package versions were published.
  • Users are advised to check installed versions and update to the latest safe ones.

The TanStack team is working on regaining control, but the aftertaste remains. This is reminiscent of the event-stream incident, only this time a popular router was targeted.

METABYTE studio's comment: Another reminder that supply chain attacks aren't just about office coffee — they're about npm install too. Always verify hashes and use lock files, or your project might end up mining for someone else.

NEXT STEP

Liked the approach?

We apply the same principles to client projects: AI, automation, products that don't die after launch.