TanStack NPM Packages Compromised

Hacker News Top News

Summary

Reports indicate a security compromise affecting TanStack NPM packages, impacting developers using the TanStack Router and Start frameworks.

No content available
Original Article
View Cached Full Text

Cached at: 05/11/26, 09:53 PM

TanStack/router

Source: https://github.com/TanStack/router

TanStack Router

TanStack Router

A modern router designed for type safety, data‑driven navigation, and seamless developer experience.

  • End‑to-end type safety (routes, params, loaders)
  • Schema‑driven search params with validation
  • Built‑in caching, prefetching & invalidation
  • Nested layouts, transitions & error boundaries

Read the Router Docs →

TanStack Start

TanStack Start

A full‑stack framework built on Router, designed for server rendering, streaming, and production‑ready deployments.

  • Full‑document SSR & streaming
  • Server functions & end‑to‑end type safety
  • Deployment‑ready bundling & builds
  • All the power of TanStack Router, plus full‑stack features

Read the Start Docs →


npm downloads GitHub stars Bundle size

semantic-release Best of JS Follow @TanStack

Become a Sponsor!

Get Involved

Partners

CodeRabbit Cloudflare Netlify
Neon Clerk Convex
Sentry Prisma Strapi
Router & you?

We're looking for TanStack Router & Start Partners to join our mission! Partner with us to push the boundaries of TanStack Router & Start and build amazing things together.

LET'S CHAT

Explore the TanStack Ecosystem

… and more at TanStack.com »

Similar Articles

Postmortem: TanStack npm supply-chain compromise

Lobsters Hottest

Detailed postmortem of a supply-chain attack on TanStack's npm packages involving cache poisoning, OIDC token extraction, and credential harvesting malware. All affected versions deprecated; users advised to rotate credentials.

Our response to the TanStack npm supply chain attack

OpenAI Blog

OpenAI responds to the TanStack npm supply chain attack, stating that no user data or production systems were compromised, but two employee devices were impacted and limited credentials exfiltrated from internal code repositories.