Supply-chain compromise hits 42 TanStack npm packages

A live npm supply-chain attack pushed malicious versions of 42 TanStack packages, turning a popular frontend dependency into a credential-theft risk

SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack /* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status:
Ranked #1 on backlist 2026-05-11 (11 May 2026 UTC) · by (TANSTACK) ·

How it ranks: Backlist reads my Twitter/X timeline, scores every tweet for substance with an LLM rubric (not engagement), and publishes the daily top picks with a one-line takeaway. Curated by Surya Dantuluri.