Hostile 92% javascript Download

@tanstack/router-vite-plugin 1.166.56

Obfuscated credential theft and C2

Lone scoped optional dep on VCS commitDetached self re-exec behavior

Also flagged by https://falhumaid.github.io/DFIR_Radar_RSS/rss.xml (Analyse de l’attaque de la supply chain TanStack), https://feeds.feedburner.com/TheHackersNews (CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories), osv (MAL-2026-3480: Malicious code in @tanstack/router-vite-plugin (npm)) +3 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.