people · May 21, 2026
Snyk Posts Details on TanStack npm Supply Chain Compromise from May 11, 2026
Share the canonical public link.
Snyk published analysis of the TanStack npm packages compromised on May 11, 2026 between 19:20 and 19:26 UTC. Snyk reported 84 malicious artifacts across 42 packages in the @tanstack namespace produced via hijacked GitHub Actions runner with valid SLSA Build Level 3 provenance. The incident spread to Mistral AI and UiPath targets with @tanstack/react-router alone exceeding 12.7 million weekly downloads while Snyk Security Database covered remediation for 170+ affected packages by end of day. Snyk provided free trial coverage and scans against its database for the related LiteLLM PyPI attack as well.