CVE-2026-45321: TanStack Unspecified Vulnerability
Critical severity, CVSS 9.6. Actively exploited: in CISA KEV since 2026-05-27. EPSS: 1.1% chance of exploitation in the next 30 days.
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.
Affected products
- ABHISHAKE1 Supersurkhet/cli: version 0.0.2 only; version 0.0.3 only; version 0.0.4 only; version 0.0.5 only; version 0.0.6 only; version 0.0.7 only
- ABHISHAKE1 Supersurkhet/sdk: version 0.0.2 only; version 0.0.3 only; version 0.0.4 only; version 0.0.5 only; version 0.0.6 only; version 0.0.7 only
- ABHISHAKE1 Taskflow-Corp/cli: version 0.1.24 only; version 0.1.25 only; version 0.1.26 only; version 0.1.27 only; version 0.1.28 only; version 0.1.29 only
- Agentworkhq Agentwork-CLI: version 0.1.4 only; version 0.1.5 only
- Antoinebcx Ml-Toolkit-Ts: version 1.0.4 only; version 1.0.5 only
- Antoinebcx Ml-Toolkit-Ts/preprocessing: version 1.0.2 only; version 1.0.3 only
- Antoinebcx Ml-Toolkit-Ts/xgboost: version 1.0.3 only; version 1.0.4 only
- Beproduct Beproduct/nestjs-Auth: version 0.1.2 only; version 0.1.3 only; version 0.1.4 only; version 0.1.5 only; version 0.1.6 only; version 0.1.7 only; …
- Christianalares Git-Git-Git: version 1.0.8 only; version 1.0.9 only; version 1.0.10 only; version 1.0.12 only
- Christianalares Git Branch Selector: version 1.3.3 only; version 1.3.4 only; version 1.3.5 only; version 1.3.7 only
- Christianalares Nextmove-Mcp: version 0.1.3 only; version 0.1.4 only; version 0.1.5 only; version 0.1.7 only
- Christianalares Tolka/cli: version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; version 1.0.6 only
- Dirigible Dirigible-Ai/sdk: version 0.6.2 only; version 0.6.3 only
- Guardrailsai Guardrails Ai: version 0.10.1 only
- Kilbot Tallyui/components: version 1.0.1 only; version 1.0.2 only; version 1.0.3 only
- Kilbot Tallyui/connector-Medusa: version 1.0.1 only; version 1.0.2 only; version 1.0.3 only
- Kilbot Tallyui/connector-Shopify: version 1.0.1 only; version 1.0.2 only; version 1.0.3 only
- Kilbot Tallyui/connector-Vendure: version 1.0.1 only; version 1.0.2 only; version 1.0.3 only
- Kilbot Tallyui/connector-Woocommerce: version 1.0.1 only; version 1.0.2 only; version 1.0.3 only
- Kilbot Tallyui/core: version 0.2.1 only; version 0.2.2 only; version 0.2.3 only
- Kilbot Tallyui/database: version 1.0.1 only; version 1.0.2 only; version 1.0.3 only
- Kilbot Tallyui/pos: version 0.1.1 only; version 0.1.2 only; version 0.1.3 only
- Kilbot Tallyui/storage-Sqlite: version 0.2.1 only; version 0.2.2 only; version 0.2.3 only
- Kilbot Tallyui/theme: version 0.2.1 only; version 0.2.2 only; version 0.2.3 only
- Linuxfoundation Opensearch: version 3.6.2 only
- and 146 more
Published 2026-05-12. Last modified 2026-06-17.