A vulnerability has been reported in multiple @tanstack/* packages which allowed an attacker to publish malicious versions of the packages. The malicious version could be used to obtain sensitive information on the targeted systems.
Target Audience:
Organizations, developers, and individuals using affected @tanstack/* packages from the npm registry.
Risk Assessment:
Critical risk of information disclosure and credential compromise.
Impact Assessment:
Exposure of sensitive credentials and unauthorized access to affected environments.
The information provided herein is on "as is" basis, without warranty of any kind.