npm package report

Is @tanstack/history safe?

Confirmed malicious. Do not install it, and remove it where it has been installed.

Do not install this package

CRITICAL

credential_stealer. Confirmed 2026-05-11, OSV malicious-package feed (Google / OpenSSF).

// what we observed

--- -= Per source details. Do not edit below this line.=- Source: ghsa-malware (d40d7bafa18dd8987c0ee75b8ffccfc7db076f4521961472d0830ef93a03994e) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it. Source: google-open-source-security (5e1924464368f0c5816ee84e000cc47017f44045140feafbbc9e685d847ed5a5) This package was compromised as part of the "Mini Shai-Hulud is back" worm by the TeamPCP threat actor. The package will steal credentials and then propogate it to every package it has access to. The package also attempts to remain persistent.

mitre ttp
T1056
// versions and what to do
Malicious
all versions
Clean
none confirmed

Remove it from every machine and lockfile it reached. Treat any credentials, tokens and SSH keys present on those machines as exposed and rotate them. Check CI runners and container images that installed it.

npm uninstall @tanstack/history

OSV record

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


      cvss
      0.0
      critical

      severity out of 10

      epss
      0.00%
      medium

      chance of exploitation in 30 days, 63rd percentile of all CVEs

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-g7cv-rxg3-hmpx, the advisory selected below

      // 1 advisories

      GHSA-g7cv-rxg3-hmpx

      CRITICALexploited in the wildCVE-2026-45321
      // summary

      On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/ packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pullrequesttarget "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity.

      Each affected package received exactly two malicious versions, published a few minutes apart.

      // impact

      A user installing any affected version executes a payload (~2.3 MB obfuscated routerinit.js) at install time that:

      • Harvests credentials from common locations:
      • AWS instance metadata (IMDS) and Secrets Manager
      • GCP metadata service
      • Kubernetes service-account tokens
      • HashiCorp Vault tokens
      • ~/.npmrc (npm tokens)
      • GitHub tokens (env vars, gh CLI config, .git-credentials)
      • SSH private keys (~/.ssh/)
      • Exfiltrates harvested data over the Session/Oxen messenger file-upload network (filev2.getsession.org, seed{1,2,3}.getsession.org). This is end-to-end encrypted with no attacker-controlled C2, so blocking by IP or domain is the only network mitigation.
      • Enumerates packages that the victim maintains via registry.npmjs.org/-/v1/search?text=maintainer: and republishes them with the same injection, propagating the compromise across npm.

      Any developer or CI environment that ran npm install, pnpm install, or yarn install against an affected version on 2026-05-11 should be considered compromised. All credentials accessible to the install process should be rotated immediately. Cloud audit logs should be reviewed for activity originating from the affected hosts during and after the install window.

      // detection

      Inspect the published manifest of any pinned @tanstack/ version. Malicious manifests contain this exact optionalDependencies entry:

      "optionalDependencies": {
        "@tanstack/setup": "github:tanstack/router#79ac49eedf774dd4b0cfa308722bc463cfe5885c"
      }

      To check a version without running install scripts:

      npm pack @tanstack/@   # downloads tarball; does NOT execute lifecycle scripts
      tar -xzf *.tgz
      grep -A3 optionalDependencies package/package.json
      ls -la package/router_init.js   # malicious payload, ~2.3 MB, present at package root

      The payload file routerinit.js is approximately 2.3 MB of obfuscated JavaScript. It is placed at the tarball root and is intentionally not declared in the package's "files" array, so it does not appear in the package's documented contents.

      // mechanism

      @tanstack/setup is not a real package on the npm registry. The github:tanstack/router#79ac49ee... specifier resolves to an orphan commit pushed to a fork in the tanstack/router GitHub fork network. GitHub serves commits across the entire fork network for git-URL dependencies, so the attacker did not require write access to TanStack/router itself — only the ability to fork and push to their own fork.

      When npm processes the optional dependency, it:

      • Fetches the orphan commit from the fork network.
      • Installs the commit's declared dependencies (which include a real bun binary).
      • Runs the commit's prepare lifecycle script: bun run tanstackrunner.js && exit 1. The trailing exit 1 causes the optional install to fail, after which npm silently discards it — leaving no nodemodules trace.
      • The tanstackrunner.js script in turn executes routerinit.js from the host package's tarball.
      // patches

      Affected versions are being deprecated on npm with a SECURITY: notice. Where npm policy allows (no existing third-party dependents), affected versions are also being unpublished. The npm security team has been engaged to pull tarballs server-side for versions that cannot be unpublished.

      Clean follow-up releases are being prepared. Update to the patched version listed in the affected-products table for each package, then reinstall from a clean lockfile.

      // workarounds

      Until clean follow-up releases are available:

      • Pin every @tanstack/ dependency to a known-good version published before 2026-05-11 19:00 UTC. The last known-good version for most affected packages was published on 2026-03-15.
      • Delete nodemodules and the lockfile, then reinstall to ensure no transitive dependency resolves to a malicious version.
      • Configure npm to skip lifecycle scripts on install (npm config set ignore-scripts true) as a temporary defense-in-depth measure.
      • For CI, audit any pipeline that ran install against @tanstack/ between 19:20 and 19:30 UTC on 2026-05-11. Treat the runner as compromised and rotate any secrets it had access to.
      // indicators of compromise

      | Indicator | Value | |---|---| | Malicious git ref | github:tanstack/router#79ac49eedf77 | | Fictitious package name | @tanstack/setup | | Payload filename | routerinit.js (~2.3 MB, package root, undeclared in files) | | Helper filename in orphan commit | tanstackrunner.js | | Exfiltration network | filev2.getsession.org, seed1.getsession.org, seed2.getsession.org, seed3.getsession.org | | Second-stage payload URLs | https://litter.catbox.moe/h8nc9u.js, https://litter.catbox.moe/7rrc6l.mjs | | Poisoned cache key | Linux-pnpm-store-6f9233a50def742c09fde54f56553d6b449a535adf87d4083690539f49ae4da11 | | Publish window (UTC) | 2026-05-11 19:20 — 19:26 | | Publish mechanism | GitHub Actions OIDC trusted publisher (oidc:db7d6f54-05d5-412b-8a10-e7a8398b303e) | | Workflow runs | https://github.com/TanStack/router/actions/runs/25613093674 (attempt 4), https://github.com/TanStack/router/actions/runs/25691781302 | | Attacker GitHub accounts | zblgg (id 127806521), voicproducoes (id 269549300) | | Attacker fork (renamed to evade detection) | https://github.com/zblgg/configuration |

      // credits// references
      • Public incident tracking issue: https://github.com/TanStack/router/issues/7383
      • Related research:
      • Adnan Khan, "The Monsters in Your Build Cache: GitHub Actions Cache Poisoning" (May 2024)
      • GitHub Security Lab, "Keeping your GitHub Actions and workflows secure: Preventing Pwn Requests"
      • StepSecurity, "tj-actions/changed-files action is compromised" (March 2025) — the malicious payload reuses this incident's runner-memory extraction technique verbatim
      // cvss v3.1 vector

      CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

      Attack vector
      Network
      Attack complexity
      Low
      Privileges required
      None
      User interaction
      Required
      Scope
      Changed
      Confidentiality
      High
      Integrity
      High
      Availability
      High

      Checked 2026-09-26 at 01:03 UTC. The most recent advisory here was published 2026-05-12. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.