Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Threat actors compromised TanStack’s npm publishing pipeline and released malicious package versions containing credential-stealing malware, executing a supply chain attack against any organization whose software build process consumes TanStack npm packages. CISA has added this to the Known Exploited Vulnerabilities catalog, indicating active exploitation, with a remediation deadline of June 10, 2026. Any organization with TanStack packages in its dependency tree faces risk of credential theft and downstream environment compromise through infected builds. Although the EPSS probabilistic score is low (0.027%), CISA’s KEV inclusion indicates active exploitation is confirmed; probabilistic scoring should not be used to reduce remediation priority.

Author

Tech Jacks Solutions