npm package
@tanstack/router-ssr-query-core
pkg:npm/%40tanstack/router-ssr-query-core
Malware
2 malicious versions on record
One or more versions of this package have been flagged as containing malicious code. Audit any system that installed an affected version.
- MAL-2026-3478Malicious code in @tanstack/router-ssr-query-core (npm)May 12, 2026
- GHSA-943h-v9jx-69h5Malware in @tanstack/router-ssr-query-coreMay 12, 2026
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-45321 | Cri | 9.6 | KEV | >= 1.168.3, < 1.168.7 | 1.168.7 | May 12, 2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publis |
- affected >= 1.168.3, < 1.168.7fixed 1.168.7
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publis