{
  "id": 11100854,
  "title": "TanStack npm supply-chain attack: how a Dependabot bump spread a worm",
  "url": "https://urgent.news/2026/10/01/tanstack-npm-supply-chain-attack-how-a-dependabot-bump-spread-a-worm",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-01T03:46:44.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/axrisi/tanstack-npm-supply-chain-attack-how-a-dependabot-bump-spread-a-worm-1h4l"
  },
  "original_language": "en",
  "account": "On May 11, 2026, a malicious worm infiltrated 84 versions of 42 TanStack npm packages, all bearing valid provenance, originating from the company's own release pipeline. Two and a half hours later, a Dependabot pull request introduced two of those compromised versions into a small aviation-data project, resulting in the maintainer's publish token being used to create 110 more malicious versions within 95 minutes. Known as the TanStack npm supply-chain attack, this incident highlights the vulnerability of the npm supply chain without any password phishing or human intervention, except for a single click. The attack began when a fork of TanStack/router, renamed and opened for pull request #7378, executed malicious code. It saved a 1.1 GB cache, which later served as the foundation for the worm to exfiltrate the publish token from the runner's memory. The worm published 84 versions of @tanstack/* packages and then used Dependabot's routine grouped bump to distribute 110 malicious versions of @squawk/* packages, causing extensive damage across the npm ecosystem.",
  "summary": "On May 11, 2026, a worm published 84 malicious versions of 42 TanStack packages to npm, with valid provenance, from TanStack's own release pipeline. Two and a half hours later a Dependabot pull request pulled two of those versions into a small aviation-data project, and a single merge turned its maintainer's publish token into 110 more malicious versions in 95 minutes. The TanStack npm…",
  "key_points": [
    "Malicious worm infiltrated 84 TanStack npm packages on May 11, 2026",
    "Dependabot pull request introduced compromised versions into aviation project",
    "Worm used publish token to create 110 malicious versions within 95 minutes"
  ],
  "editors_take": "This incident shows that a single click can be all that's needed to initiate a supply-chain attack, highlighting the vulnerability of the npm ecosystem to infiltration through automated processes.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}