Observed Signal · May 29, 2026 · Security Incident / Postmortem · Source: DEV Community · Impact: 3/5 · Sentiment: Negative

TanStack publishes postmortem for 42-package npm compromise

Executive Signal Summary

On May 11, 2026 an attacker published 84 malicious versions across 42 packages in the @tanstack npm scope by hijacking the build pipeline rather than stealing maintainer credentials. The packages carried valid SLSA provenance because the attacker extracted short-lived OIDC tokens from runner memory and republished from within the compromised CI run. An external researcher from StepSecurity flagged the anomaly within minutes; TanStack deprecated the malicious releases ~1 hour 43 minutes after first publish and npm removed tarballs later the same day. The postmortem details a three-primitive chain (a 'Pwn Request' using pull_request_target, cross-trust cache poisoning, and OIDC token extraction), lists affected downstream packages, names advisory GHSA-g7cv-rxg3-hmpx, and provides a checklist of mitigations for projects using GitHub Actions.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Demonstrates a novel supply-chain attack that defeats SLSA provenance by hijacking CI runs; affects trust in package provenance and CI practices across many projects using GitHub Actions.

SIGNAL RADAR

Track NPM Capital Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Compromise occurred May 11, 2026 between 19:20 and 19:26 UTC with 84 malicious versions across 42 @tanstack packages
  • Self-propagation expanded reach to 170+ packages; secondary victims included @mistralai/mistralai, 40+ @uipath packages and 19 aviation-related packages
  • External researcher (ashishkurmi, StepSecurity) detected the malicious publish within six minutes; TanStack deprecated the releases ~1 hour 43 minutes after first publish
  • This is the first documented case of a malicious npm package carrying valid SLSA provenance because the attacker extracted OIDC tokens from runner memory and published from the pipeline
  • Advisory referenced: GHSA-g7cv-rxg3-hmpx; the postmortem provides a mitigation checklist (avoid unsafe pull_request_target patterns, isolate cache keys, scope OIDC permissions, check for persistence artifacts)
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: May 29, 2026
Original Coverage Title: “TanStack shipped a postmortem for the 42-package npm compromise. Here is what every project should change this week.”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

InfrastructureMay 31, 2026

23,000+ Repos Had Secrets Stolen via Compromised GitHub Action

A DevOps/security post documents a major supply-chain compromise of GitHub Actions where a popular action (tj-actions/changed-files) was hijacked in March 2025, exposing AWS keys, GitHub PATs, RSA private keys and npm tokens for over 23,000 teams. The vulnerability was tracked as CVE-2025-30066. The author analyzes this and related incidents (Ultralytics December 2024, Trivy February 2026), identifies recurring root causes (tag-pinned actions, pull_request_target misuse, overly permissive GITHUB_TOKEN scopes) and presents seven practical CI/CD hardening techniques: pin actions to commit SHAs, use OIDC, restrict GITHUB_TOKEN permissions, treat workflow files like production code, use automated workflow scanners (e.g., Zizmor), mirror critical actions/private registries, and enforce branch protection and deployment gates. The piece includes a checklist of quick wins and describes how the author applied these principles while building Nexloy.

Read assessment
SecurityMay 14, 2026

OpenAI: Hackers Stole Data After Supply-Chain Attack

OpenAI confirmed on May 14, 2026 that two employees’ devices were impacted by a recent supply‑chain attack that abused a compromised open‑source project (TanStack). After investigation, OpenAI said attackers accessed a limited subset of internal source code repositories and stole “only limited credential material,” but found no evidence that user data, production systems or intellectual property were compromised. TanStack disclosed that attackers published 84 malicious npm package versions during a six‑minute window; the malicious packages were designed to steal credentials and self‑propagate. As a precaution, OpenAI is rotating digital certificates used to sign products, an action that will require macOS users to update the app. The incident is part of a broader wave of supply‑chain compromises targeting developer tooling.

Read assessment
InfrastructureMay 13, 2026

pnpm 11 release bolsters npm supply-chain security

The article explains that pnpm 11, released April 28, 2026, introduces stronger security-by-default settings for JavaScript dependency installs in response to recent npm supply-chain attacks — notably the May 11, 2026 TanStack compromise. The TanStack incident involved an attacker publishing 84 malicious versions across 42 @tanstack/* packages by exploiting GitHub Actions workflow trust boundaries (a "pull_request_target" "Pwn Request" pattern), cache poisoning, and runtime extraction of an OIDC token. pnpm 11's default protections include a 24-hour delay for newly published packages, blocking exotic/non-registry subdependencies, stricter build permissions, and dependency verification before execution. The piece frames pnpm 11 as a practical mitigation that would have limited exposure from fast, malicious releases and emphasizes package managers' growing role in software supply-chain security.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.