At least five TanStack Router npm packages have been compromised with malicious payloads targeting credential theft. The affected versions contain a heavily obfuscated 2.3 MB script and a doctored package.json that pulls a payload via a GitHub cross-fork 'ghost commit' using a prepare script. The malware targets AWS instance/task-role credentials, HashiCorp Vault tokens, GitHub tokens, and npm tokens, exfiltrating them via Session messenger. Developers should immediately stop installing affected versions, audit recent installs since 2026-05-11 19:20 UTC, rotate all secrets on potentially compromised hosts, and hunt for outbound connections to filev2.getsession.org. StepSecurity detected the compromise through automated analysis of new npm releases.

3m read timeFrom stepsecurity.io
Post cover image
Table of contents
What we know so farWhat you should do right nowHow StepSecurity detected thisWhat's next
3 Comments

Sort: