TanStack npm supply-chain attack: how a Dependabot bump spread a worm
On May 11, 2026, a worm published 84 malicious versions of 42 TanStack packages to npm, with valid provenance, from TanStack's own release pipeline. Two and a half hours later a Dependabot pull request pulled two of those versions into a small aviation-data project, and a single merge turned its maintainer's publish token into 110 more malicious versions in 95 minutes. The TanStack npm…
On May 11, 2026, a malicious worm infiltrated 84 versions of 42 TanStack npm packages, all bearing valid provenance, originating from the company's own release pipeline. Two and a half hours later, a Dependabot pull request introduced two of those compromised versions into a small aviation-data project, resulting in the maintainer's publish token being used to create 110 more malicious versions within 95 minutes.
Known as the TanStack npm supply-chain attack, this incident highlights the vulnerability of the npm supply chain without any password phishing or human intervention, except for a single click. The attack began when a fork of TanStack/router, renamed and opened for pull request #7378, executed malicious code. It saved a 1.1 GB cache, which later served as the foundation for the worm to exfiltrate the publish token from the runner's memory.
The worm published 84 versions of @tanstack/* packages and then used Dependabot's routine grouped bump to distribute 110 malicious versions of @squawk/* packages, causing extensive damage across the npm ecosystem.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.