The TanStack npm Hack: What Happened, How to Check, and What Should Change
On 11 May 2026, 84 malicious package versions were published to npm under the @tanstack namespace — by the project's own publishing pipeline. Here is what happened, how to check your systems, and what the industry should change.