Skip to content

Tanstack Compromise Checker

Forensics & Incident Response

Detects and mitigates the TanStack npm supply‑chain attack across developer machines, repositories, and CI runners

Shell Latest v1.2.0 · 2mo ago Security brief →

Features

  • Scans for dead‑man's switch daemons and persistence mechanisms on macOS/Linux/WSL2/Git Bash
  • Checks installed `@tanstack/*` packages against a live list of compromised versions (online mode)
  • Audits configuration files, environment variables, and credential stores for stolen tokens
  • Runs as a Bash script, Docker container, or GitHub Action with JSON output for CI integration

Recent releases

View all 6 releases →
No immediate action
v1.2.0 Security relevant

Security fix GHSA-g7cv-rxg3-hmpx

No immediate action
v1.1.2 Security relevant

GHSA‑g7cv‑rxv3‑hmpx fix

No immediate action
v1 Security relevant

GHSA‑g7cv‑rxg3‑hmpx

No immediate action
v1.1.1 Security relevant

Security fix GHSA-g7cv-rxg3-hmpx

No immediate action
v1.1.0 Security relevant

GHSA‑g7cv‑rxg3‑hmpx fix

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
2
Forks
0
Languages
Shell Dockerfile

Install & Platforms

Install via
shell-script docker
Platforms
linux macos windows arm64

Beta — feedback welcome: [email protected]