Knox CVE Database
/
CVE-2026-45321
Critical
9.6
Ransomware use

CVE-2026-45321: TanStack Unspecified Vulnerability

TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.

Added to the CISA KEV catalog:
May 27, 2026

Overview

Eighty-four malicious versions of TanStack npm packages were published on May 11, 2026, by an attacker who hijacked the project's own GitHub Actions CI/CD pipeline through a chained exploit. Any developer or CI system that ran a package install against one of the 42 affected @tanstack/* packages during a six-minute window that day executed credential-stealing malware at install time. The payload harvests cloud provider tokens, SSH keys, npm credentials, and GitHub tokens from the install host, exfiltrates them, and self-propagates by republishing other packages the victim maintains with the same injection. This attack has been attributed to the TeamPCP threat group and is associated with known ransomware activity.

Vulnerability details

Affected vendor
TanStack
Affected product
TanStack
Weakness type (CWE)
CWE-506

This incident is classified as embedded malicious code (CWE-506): the attacker injected an obfuscated ~2.3 MB payload file, router_init.js, into otherwise-legitimate npm package tarballs. The delivery mechanism exploited npm's package lifecycle: a malicious optionalDependencies entry pointing to a fictitious package (@tanstack/setup) resolved to an orphan commit on an attacker-controlled GitHub fork. When npm processed the dependency, it fetched the commit, ran its prepare lifecycle script, and executed the payload. The trailing exit 1 in the prepare script caused the optional install to fail silently, leaving minimal traces in npm logs while the payload had already run.


The attacker reached this position by chaining three weaknesses against TanStack's CI/CD pipeline: a pull_request_target Pwn Request misconfiguration allowed a fork PR to trigger privileged workflows without approval; GitHub Actions cache poisoning across the fork-to-base trust boundary planted a malicious pnpm store that the release workflow later restored; and runtime memory extraction read the GitHub Actions Runner.Worker process via /proc/<pid>/mem, targeting JSON objects matching the pattern {"value":"...","isSecret":true} to extract every configured workflow secret, including the OIDC token used to publish to npm. Any developer or CI system that installed an affected version during the publish window should be treated as fully compromised.

Severity and impact

9.6
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Changed
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Known

Detection and monitoring

  • Inspect the package.json of any pinned @tanstack/* version for an optionalDependencies entry referencing @tanstack/setup or a github:tanstack/router# git URL; presence of either field in a tarball is a definitive indicator of compromise.
  • Check the package root of any installed @tanstack/* tarball for a file named router_init.js approximately 2.3 MB in size and not declared in the package's files array; its presence confirms the malicious payload was delivered.
  • During npm install, monitor for child processes spawned by bun.exe or bun making outbound connections to filev2.getsession.org, seed1.getsession.org, seed2.getsession.org, or seed3.getsession.org; these are the exfiltration endpoints and have no legitimate role in a package install.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
June 10, 2026

Additional hardening

  • Remove all affected @tanstack/* versions (published 2026-05-11 between 19:20 and 19:26 UTC) and pin dependencies to versions published before that window; see the vendor advisory in References for the full affected-version table.
  • Any host that ran npm install, pnpm install, or yarn install against an affected version on 2026-05-11 should be treated as compromised: rotate AWS, GCP, Kubernetes, Vault, GitHub, npm, and SSH credentials accessible from that host immediately.
  • Set npm config set ignore-scripts true in CI environments as a compensating control to prevent lifecycle scripts from executing during install; audit any pipeline that ran against @tanstack/* packages during the publish window.
  • Restrict outbound network access from CI runners to known-good registries and block connections to Session/Oxen CDN endpoints (filev2.getsession.org, seed1-3.getsession.org) at the network perimeter to limit exfiltration reach.

Key dates

Published (NVD)
May 11, 2026
Added to CISA KEV
May 27, 2026
Remediation deadline
June 10, 2026
Last updated
June 17, 2026

References

Frequently asked questions

Does CVE-2026-45321 affect my FedRAMP authorization?

If TanStack runs inside your authorization boundary, CVE-2026-45321 affects your FedRAMP authorization directly. This Critical-severity vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of June 10, 2026 has already passed. An unpatched KEV inside your boundary is an assessor finding. An overdue one is a finding your assessor and sponsoring agency can see right now. Remediate it immediately or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-45321?

Knox does not patch your software. Remediating TanStack is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage that support your documentation for the next assessment cycle. Applying the fix is yours to own; maintaining a defensible compliance posture while you do it is not something you have to manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. For a CVE like CVE-2026-45321, that means exposure surfaces during continuous monitoring rather than waiting until an assessor flags it at a scheduled review.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-45321's remediation deadline of June 10, 2026 has passed. What happens now?

If CVE-2026-45321 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing it out now and documenting the circumstances of the delay is what keeps your authorization intact and the agency relationship on solid ground.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.