CVE-2026-45321: CWE-506: Embedded Malicious Code in @tanstack arktype-adapter
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.
AI Analysis
Technical Summary
CVE-2026-45321 describes a supply chain attack on the @tanstack npm packages, including arktype-adapter, where an attacker leveraged a combination of a pull_request_target misconfiguration, GitHub Actions cache poisoning, and runtime memory extraction of OIDC tokens to publish malicious versions under a trusted identity. This attack resulted in 84 malicious versions being published across 42 packages, each receiving two malicious versions. The attack exploited the trusted GitHub Actions OIDC publisher binding without modifying the publish workflow itself. The affected versions of @tanstack/arktype-adapter are exactly 1.166.12 and 1.166.15. The CVSS score is 9.6 (critical), indicating high impact on confidentiality, integrity, and availability.
Potential Impact
The attack allows an adversary to publish malicious code under a trusted identity, potentially leading to credential theft and compromise of systems that consume the affected packages. The high CVSS score (9.6) reflects critical impact on confidentiality, integrity, and availability. This compromises the software supply chain trust for the affected @tanstack packages, including arktype-adapter versions 1.166.12 and 1.166.15.
Mitigation Recommendations
No official patch or remediation level has been provided yet. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid using the affected versions (=1.166.12 and =1.166.15) of @tanstack/arktype-adapter and related packages. Monitor vendor channels for updates and consider verifying package integrity through alternative means.
CVE-2026-45321: CWE-506: Embedded Malicious Code in @tanstack arktype-adapter
Description
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.
CVSS v3.1
Score 9.6critical
Affected software
@tanstack
arktype-adapter
@tanstack
eslint-plugin-router
@tanstack
eslint-plugin-start
@tanstack
history
@tanstack
nitro-v2-vite-plugin
@tanstack
react-router
@tanstack
react-router-devtools
@tanstack
react-router-ssr-query
@tanstack
react-start
@tanstack
react-start-client
@tanstack
react-start-rsc
@tanstack
react-start-server
@tanstack
router-cli
@tanstack
router-core
@tanstack
router-devtools
@tanstack
router-devtools-core
@tanstack
router-generator
@tanstack
router-plugin
@tanstack
router-ssr-query-core
@tanstack
router-utils
@tanstack
outer-vite-plugin
@tanstack
solid-router
@tanstack
solid-router-devtools
@tanstack
solid-router-ssr-query
@tanstack
solid-start
@tanstack
solid-start-client
@tanstack
solid-start-server
@tanstack
start-client-core
@tanstack
start-fn-stubs
@tanstack
start-plugin-core
@tanstack
start-server-core
@tanstack
start-static-server-functions
@tanstack
start-storage-context
@tanstack
valibot-adapter
@tanstack
virtual-file-routes
@tanstack
vue-router
@tanstack
vue-router-devtools
@tanstack
vue-router-ssr-query
@tanstack
vue-start
@tanstack
vue-start-client
@tanstack
vue-start-server
@tanstack
zod-adapter
pkg:npm/@tanstack/arktype-adapterRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-45321 describes a supply chain attack on the @tanstack npm packages, including arktype-adapter, where an attacker leveraged a combination of a pull_request_target misconfiguration, GitHub Actions cache poisoning, and runtime memory extraction of OIDC tokens to publish malicious versions under a trusted identity. This attack resulted in 84 malicious versions being published across 42 packages, each receiving two malicious versions. The attack exploited the trusted GitHub Actions OIDC publisher binding without modifying the publish workflow itself. The affected versions of @tanstack/arktype-adapter are exactly 1.166.12 and 1.166.15. The CVSS score is 9.6 (critical), indicating high impact on confidentiality, integrity, and availability.
Potential Impact
The attack allows an adversary to publish malicious code under a trusted identity, potentially leading to credential theft and compromise of systems that consume the affected packages. The high CVSS score (9.6) reflects critical impact on confidentiality, integrity, and availability. This compromises the software supply chain trust for the affected @tanstack packages, including arktype-adapter versions 1.166.12 and 1.166.15.
Mitigation Recommendations
No official patch or remediation level has been provided yet. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid using the affected versions (=1.166.12 and =1.166.15) of @tanstack/arktype-adapter and related packages. Monitor vendor channels for updates and consider verifying package integrity through alternative means.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-11T20:50:30.539Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a028743cbff5d86108b505d
Added to database: 05/12/2026, 01:49:55 UTC
Last enriched: 08/04/2026, 13:26:12 UTC
Last updated: 09/13/2026, 22:01:34 UTC
Views: 354
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.