Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-45321
CVE
CVE-2026-45321
View on NVD ↗
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
MITRE ATT&CK TTPs
1
T1195.002
Compromise Software Supply Chain
Initial Access
Source Articles
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
CrowdSec disclosed that approximately 170 of its private GitHub repositories were copied on May 22, 2026, due to a supply chain attack stemming from the compromise of a former employee's laptop via malicious TanStack npm packages. The attacker leveraged a GitHub OAuth token from the former employee's account, which had not been revoked promptly after departure. The breach exposed source code, including internal automation scripts, data science models, and the consensus algorithm used in its blocklist system, as well as sensitive information such as 83 user email addresses and investor details from 2020. The initial compromise is linked to CVE-2026-45321, a supply chain attack on TanStack that stole developer credentials.
hacker-news
Sep 19, 2026