← Vulnerability feed

Vulnerability record · CVE-2026-45321 · published 12 May 2026

CVE-2026-45321: TanStack npm packages published with credential-stealing malware via CI/CD chain

Tanstack · Tanstack\/Arktype Adapter

Eighty-four malicious versions across 42 @tanstack/* npm packages were published on 2026-05-11 using the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, without modifying the publish workflow. The attacker chained a pull_request_target misconfiguration, GitHub Actions cache poisoning across the fork-to-base trust boundary, and runtime extraction of the OIDC token from the runner process. Because the packages were published under a trusted identity, downstream installs would pull credential-stealing malware.

9.6 CVSS 3.1 Critical CISA KEV since 27 May 2026 Known ransomware use EPSS 1.1% · top 37.0% CWE-506 · CWE-506
9.6CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
150Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.6, active KEV listing with ransomware use, and a confirmed supply-chain compromise of widely used packages make this an urgent patching and credential-rotation case.

What it is

Eighty-four malicious versions across 42 @tanstack/* npm packages were published on 2026-05-11 using the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, without modifying the publish workflow. The attacker chained a pull_request_target misconfiguration, GitHub Actions cache poisoning across the fork-to-base trust boundary, and runtime extraction of the OIDC token from the runner process. Because the packages were published under a trusted identity, downstream installs would pull credential-stealing malware.

Impact

Anyone installing an affected package version receives credential-stealing malware, giving the attacker access to secrets and credentials in the installer's environment. The trusted publish path also undermines normal supply-chain trust signals.

Attack surface

Reached through the npm registry: victims install a malicious package version, so exploitation requires the victim to pull the affected release (UI:R in the vector). The attacker side required no authentication to the npm registry, abusing the CI/CD trusted-publisher binding instead.

Exploitation

CISA added this to KEV on 2026-05-27 with a 2026-06-10 due date and flags known ransomware campaign use; EPSS is 0.02342 (82.8th percentile). References are tagged Exploit and Vendor Advisory, indicating public exploitation detail exists.

What to do

  • Remove or pin away from the 84 malicious @tanstack/* versions and reinstall from known-good releases.
  • Rotate any credentials, tokens, or secrets exposed to environments where affected versions were installed.
  • Audit GitHub Actions workflows for pull_request_target misconfigurations and restrict cache scope across fork/base boundaries.
  • Harden OIDC trusted-publisher bindings and monitor npm publish events for unexpected versions.
  • Follow CISA KEV required actions and BOD 22-01 guidance for affected cloud services.

Detection

  • Search lockfiles and build logs for the 42 affected @tanstack/* packages and the two malicious versions per package published 2026-05-11 19:20-19:26 UTC.
  • Monitor npm registry and CI publish logs for unexpected version publishes under trusted-publisher identities.
  • Hunt for outbound credential exfiltration or unusual process memory access on GitHub Actions runners.
  • Review GitHub Actions cache writes crossing fork-to-base boundaries for poisoning attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-45321 to the Known Exploited Vulnerabilities catalog on 27 May 2026 as "TanStack Unspecified Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 10 June 2026.

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-45321 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-8398DAEMON Tools Lite installers trojanized via supply chain compromiseAttackers breached AVB Disc Soft's build or distribution infrastructure and trojanized three signed binaries (DTHelper.exe, DiscSoftBusServiceLite.ex…KEVEPSS 0.96%analysed9.3CVE-2026-48027Nx Console VS Code extension shipped with embedded malicious codeA malicious version of the Nx Console extension, 18.95.0, was published to the Visual Studio Marketplace and OpenVSX and remained downloadable for ro…KEVEPSS 1.3%analysed9.4CVE-2026-33634Trivy and trivy-action supply chain compromise via malicious release and tagsA threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in aquasecurity/trivy-acti…KEVEPSS 1.7%analysed7.5CVE-2025-54313eslint-config-prettier npm package ships malicious install scriptVersions 8.10.1, 9.1.1, 10.1.6 and 10.1.7 of eslint-config-prettier contain embedded malicious code: installing the package runs an install.js that l…KEVEPSS 4.5%analysed9.3CVE-2025-59374ASUS Live Update client supply chain compromise with embedded malicious codeCertain builds of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modi…KEVEPSS 1.2%analysed8.6CVE-2025-30154reviewdog/action-setup GitHub Action leaks secrets to workflow logsreviewdog/action-setup@v1 was compromised on March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets into G…KEVEPSS 2.4%analysed8.6CVE-2025-30066tj-actions/changed-files GitHub Action leaks secrets via modified tagsThe tj-actions/changed-files GitHub Action was compromised: tags v1 through v45.0.7 were modified on 2025-03-14 and 2025-03-15 to point at commit 0e5…KEVEPSS 72%analysed8.7CVE-2024-4978JAVS Viewer installer ships backdoored binary with forged signatureThe Justice AV Solutions Viewer Setup 8.3.7.250-1 installer contains an embedded malicious binary signed with an unexpected Authenticode signature, m…KEVEPSS 27%analysed

Source: NIST National Vulnerability Database (record CVE-2026-45321), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.