TanStack
Profile
Organisation tracking is available to eligible accounts.
Profile narrative
TanStack operates as an open‑source software organisation that maintains and publishes libraries for modern web development. Its most widely used offering is the React Router library, which records more than twelve million weekly downloads across the npm registry. The library enables declarative routing in React applications and is a foundational component for many front‑end projects. Because of its broad adoption, TanStack holds a notable position in the JavaScript ecosystem, serving developers worldwide who rely on its tools for building single‑page applications. The organisation’s work is distributed under permissive licenses, allowing unrestricted use in both commercial and non‑commercial contexts.
On 11 May 2026, TanStack’s React Router package was compromised in a supply‑chain malware campaign identified as Mini Shai‑Hulud. Attackers exploited an orphaned commit to hijack the library’s GitHub Actions workflow, inserting a concealed dependency that fetched an obfuscated payload. The payload was executed by the Bun runtime and designed to harvest cloud credentials, SSH keys, and other secret files from infected developer machines. To maintain persistence, the malware copied itself into Visual Studio Code and Claude configuration directories on the victim’s system. Stolen data was exfiltrated via the Session messaging app, which provided an encrypted channel for the attackers. In an attempt to propagate further, the malware published additional commits that were spoofed to appear as if they originated from the Anthropic Claude bot. Researchers attributed the operation to the cloud‑focused threat group TeamPCP, noting their focus on stealing development environment secrets. Although the compromised versions were swiftly removed from registries and no registry passwords were proven stolen, analysts observed that the malware did not achieve widespread spread beyond the initial infections. The incident highlighted the risks associated with relying on orphaned commits and insufficient workflow security in open‑source projects.
Incidents
1 incident linked to this organisation.