🚨 A brand-squatting npm package impersonating TanStack shipped malicious versions that exfiltrate environment variables from developers’ machines during install.
We spoke to
@tannerlinsley, creator of
@tan_stack, who confirmed that the maintainer of the unscoped tanstack package is not associated with TanStack or the official
@tanstack/* projects in any way. The package is unrelated to the project's official CLI, and represents an ongoing brandjacking issue.
He also said TanStack has filed legal documents related to a pending trademark infringement claim against the maintainer, that the maintainer previously demanded $10,000 from him, and that TanStack has repeatedly tried, unsuccessfully, to get
@npmjs to address the situation.