GHSA-g7cv-rxg3-hmpx
GHSA-g7cv-rxg3-hmpx
malwarecriticalMalware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys. 0 of 13 watched services resolved a compromised version; 0 did so while it was still installable; none is reachable from first-party code.
no watched service resolves an affected version — nothing to draw
- lockfile resolved while installable
- L2 act now
- L1 imported
- L0 present only
- unscanned
Which of my services are exposed, and at what level?
0 act now
| service | verdict | lockfiles | pulled in via | latest commit | |
|---|---|---|---|---|---|
no watched service resolved an affected version | |||||
notes ·verdict is per service, highest across its lockfiles. unscanned means the service resolves an affected version but its source was not read — not that it is clean.
Membership is exact (RESOLVED = the lockfile's flattened install tree). Explanation paths are the 3 shortest per lockfile, not all of them.
Which versions were installable, and for how long?
84 removed
| version | published (exact) | live until | state |
|---|---|---|---|
| @tanstack/react-router-ssr-query@1.166.15first | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/router-utils@1.161.11 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/history@1.161.9 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/vue-router-ssr-query@1.166.15 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/solid-start-client@1.166.50 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/solid-router-ssr-query@1.166.15 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/react-router-devtools@1.166.16 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/vue-router-devtools@1.166.16 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/react-start-client@1.166.51 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/arktype-adapter@1.166.12 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/valibot-adapter@1.166.12 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/start-fn-stubs@1.161.9 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/solid-start-server@1.166.54 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/solid-router-devtools@1.166.16 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/zod-adapter@1.166.12 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/vue-start-client@1.166.46 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/nitro-v2-vite-plugin@1.154.12 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/start-storage-context@1.166.38 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/router-vite-plugin@1.166.53 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/router-devtools@1.166.16 | 2026-05-11 19:20:39Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/vue-start-server@1.166.50 | 2026-05-11 19:20:40Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/router-ssr-query-core@1.168.3 | 2026-05-11 19:20:40Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/virtual-file-routes@1.161.10 | 2026-05-11 19:20:40Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/vue-start@1.167.61 | 2026-05-11 19:20:40Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/start-server-core@1.167.33 | 2026-05-11 19:20:40Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/react-start-server@1.166.55 | 2026-05-11 19:20:40Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/router-devtools-core@1.167.6 | 2026-05-11 19:20:40Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/router-cli@1.166.46 | 2026-05-11 19:20:40Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/start-static-server-functions@1.166.44 | 2026-05-11 19:20:40Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/eslint-plugin-router@1.161.9 | 2026-05-11 19:20:40Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/solid-start@1.167.65 | 2026-05-11 19:20:41Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/react-start-rsc@0.0.47 | 2026-05-11 19:20:41Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/eslint-plugin-start@0.0.4 | 2026-05-11 19:20:41Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/router-generator@1.166.45 | 2026-05-11 19:20:41Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/router-plugin@1.167.38 | 2026-05-11 19:20:41Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/start-client-core@1.168.5 | 2026-05-11 19:20:41Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/react-start@1.167.68 | 2026-05-11 19:20:42Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/vue-router@1.169.5 | 2026-05-11 19:20:42Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/router-core@1.169.5 | 2026-05-11 19:20:42Z | 2026-05-12 00:12:49Zupper bound | removed |
| @tanstack/react-router@1.169.5 | 2026-05-11 19:20:42Z | 2026-05-12 00:12:49Zupper bound | removed |
notes ·live_to is an upper bound: npm publishes no takedown time; we use min(next surviving publish, advisory published).
Who pulled it in while it was still installable?
0 pin removed
| service | lockfile | resolved at | commit | in window | window |
|---|---|---|---|---|---|
no watched lockfile was committed inside the window or pins a removed version | |||||
notes ·live_from is exact (npm keeps the publish timestamp after erasing the version). live_to is an upper bound where marked — npm publishes no takedown time.
in_window: the pin was committed while the artifact was installable; it does not prove an install happened. pinned_removed: the lockfile pins a version npm has erased, which is only possible while it was live — commit time is irrelevant.
What else could the same maintainers reach?
49 packages
| package | weekly downloads | services that would be reached |
|---|---|---|
| chart.js | 8,491,458 | 2uptime-kuma, medplum |
| @tanstack/react-table | not recorded | 1documenso |
| @tanstack/arktype-adapter | not recorded | 0none |
| @tanstack/eslint-plugin-router | not recorded | 0none |
| @tanstack/eslint-plugin-start | not recorded | 0none |
| @tanstack/history | not recorded | 0none |
| @tanstack/nitro-v2-vite-plugin | not recorded | 0none |
| @tanstack/query-core | not recorded | 0none |
| @tanstack/react-query | not recorded | 0none |
| @tanstack/react-router | not recorded | 0none |
| @tanstack/react-router-devtools | not recorded | 0none |
| @tanstack/react-start | not recorded | 0none |
| @tanstack/react-start-client | not recorded | 0none |
| @tanstack/react-start-rsc | not recorded | 0none |
| @tanstack/react-start-server | not recorded | 0none |
limits ·past the computed cap the reach cell reads “— not computed” — never a 0.
49 co-maintained packages; exposure computed for the 12 most downloaded.
twofa / account_created are not exposed by the public npm registry; shown as unknown, never guessed.
'services at risk' = services resolving the co-maintained package today — the exposure IF that package is compromised next, not exposure to this incident.
Which look-alike names exist?
0 kinds

no near-names in the ingested corpus across 42 packages
notes ·The corpus is packages present in the ingested graph, so near-neighbours may be legitimate look-alikes; distance and kind are facts, 'typosquat' is a hypothesis.
What is the blast radius, service by service?
0 unscanned
notes ·0 services · 0 lockfile snapshots · 49 co-maintained packages · composed in 4.59 s