Deep Dive: TanStack npm Supply-Chain Compromise via GitHub Actions
On May 11, 2026, the TanStack open-source project suffered a significant supply-chain attack where 84 malicious versions were published across 42 packages. The attacker exploited a misconfigured GitHub Actions workflow using pull_request_target, which executed code from an unreviewed pull request in a privileged context. By chaining this with cache poisoning and OIDC token extraction from runner memory, the attacker stole publish tokens without phishing maintainers. The resulting malware, dubbed Shai-Hulud, infiltrated developer machines via optionalDependencies, stealing credentials like SSH keys and cloud tokens, and exfiltrating them using the encrypted Session messenger app to evade detection. The worm aimed to spread by compromising maintainers to inject further malicious packages. Affected users are urged to check lockfiles for specific indicators of compromise, rotate all exposed credentials, and audit their CI/CD workflows for similar vulnerabilities. This incident highlights the critical security risks associated with using pull_request_target without proper approval gates in open-source repositories.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection