CISA KEV · catalog date May 27, 2026 · first observed Jul 19, 2026
Evidence dossier
CVE-2026-45321
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
Exploited in the wild (CISA KEV since May 27, 2026). GitHub_M reports CVSS 3.1 9.6. EPSS estimates 2.3% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.
- State
- PUBLISHED
- Published
- May 12, 2026
- Updated
- Aug 4, 2026
- Evidence coverage
- 98%
Evidence chronology
What was known when
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: TanStack Unspecified Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- TanStack Unspecified Vulnerability
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCAGitHub_MOriginal evidence ↗
Record text: Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
Inspect raw assertion
- Field
container- Value
- Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 2.34% probability · 82.39th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.023420000000; percentile 0.823860000000
FIRST EPSS · score date Aug 27, 2026 · 82.4th percentile · first observed Aug 27, 2026
GitHub_M · CVSS 3.1 · first observed Aug 4, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
TanStack Unspecified Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- TanStack Unspecified Vulnerability
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
Inspect raw assertion
- Field
container- Value
- Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
2.34% probability · 82.39th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.023420000000; percentile 0.823860000000
Applicability
Cited product scope
Grouped from 53 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
213 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.166.12"}, {"status": "affected", "version": "1.166.15"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.161.9"}, {"status": "affected", "version": "1.161.12"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0.0.4"}, {"status": "affected", "version": "0.0.7"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.161.9"}, {"status": "affected", "version": "1.161.12"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.154.12"}, {"status": "affected", "version": "1.154.15"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.166.53"}, {"status": "affected", "version": "1.166.56"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.169.5"}, {"status": "affected", "version": "1.169.8"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.166.16"}, {"status": "affected", "version": "1.166.19"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.166.15"}, {"status": "affected", "version": "1.166.18"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.167.68"}, {"status": "affected", "version": "1.167.71"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.166.51"}, {"status": "affected", "version": "1.166.54"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0.0.47"}, {"status": "affected", "version": "0.0.50"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.166.55"}, {"status": "affected", "version": "1.166.58"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.166.46"}, {"status": "affected", "version": "1.166.49"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.169.5"}, {"status": "affected", "version": "1.169.8"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.166.16"}, {"status": "affected", "version": "1.166.19"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.167.6"}, {"status": "affected", "version": "1.167.9"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.166.45"}, {"status": "affected", "version": "1.166.48"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.167.38"}, {"status": "affected", "version": "1.167.41"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.168.3"}, {"status": "affected", "version": "1.168.6"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.161.11"}, {"status": "affected", "version": "1.161.14"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.169.5"}, {"status": "affected", "version": "1.169.8"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.166.16"}, {"status": "affected", "version": "1.166.19"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.166.15"}, {"status": "affected", "version": "1.166.18"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "1.167.65"}, {"status": "affected", "version": "1.167.68"}]Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.