VYPR

npm package

@tanstack/arktype-adapter

pkg:npm/%40tanstack/arktype-adapter

Malware

2 malicious versions on record

One or more versions of this package have been flagged as containing malicious code. Audit any system that installed an affected version.

Vulnerabilities (1)

  • CVE-2026-45321CriKEVMay 12, 2026
    affected >= 1.166.12, < 1.166.16fixed 1.166.16

    On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publis