SECURITY ADVISORY — TanStack npm packages
A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package.
Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down.
Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys.
If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised:
• Rotate cloud, GitHub, and SSH credentials immediately
• Audit cloud audit logs for the last several hours
• Pin to a prior known-good version and reinstall from a clean lockfile
Detection — the malicious manifest contains:
"optionalDependencies": {
"@tanstack/setup": "github:tanstack/router#79ac49ee..."
}
Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root).
Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level.
Full technical breakdown, complete package and version list, and rolling status updates:
https://t.co/Zy8qG7PA9f
Credit to the security researcher for responsible disclosure.
my workflow, use opus to create a high level plan doc. I try to include mulitple features I plan to work on
Usually thats where 100% session limit hits
Then I switch to codex, 5.5 medium feels good enough to devide the plan doc into separate spec docs (superpower skill claude)
And implement one by one
Then quick review by opus
personal update:
after nearly 2 years across community & marketing, my time at @wormhole comes to an end
started from CM and worked my way up to Sr. CM and then to ecosystem marketing along with @Maylor_Moon
learnt from some of the best peeps in this space and got to work with protocols at an infra level was definitely a lot of fun
some personal fav moments:
- got immense love from all the fellows from Day 1
- bullied Tegu with a fat cat nohornt army
- sent too many borderline nsfw jokes w/ the rifters
- pushed the @Worm_Alt acc
- went from a community role to a marketing one with everyone pushing me to do so
- worked with some amazing amazing partner protocols including @sunrisedefi and @mayan
what's next?
after taking some time off, i'm actively looking for new marketing opportunities
still bullish on this space and sectors like tradfi x crypto, tokenization/RWAs, infra layers, and specific L1/L2s
in the meantime, i'll be bringing this acc back from the dead, shitposting, playing with claude code and in rare occasions, dropping in some random gcs
to all the rifters, wardens, spaceworms, ascendants, and fellows
we shall vibe again v v soon 🐈🐈🐈
We are observing unusual activity on the protocol. We are currently investigating. Please do not deposit funds into the protocol while we investigate. This is not an April Fools joke. Proceed with caution until further notice. We’ll provide additional updates from this account.