🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
TanStack Malicious npm Package Supply Chain Compromise (CVE-2026-45321) | MSSP Advisory
High🔴 KEV ALERTConfirmed
DateMay 27, 2026
CVECVE-2026-45321
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
CISA flagged CVE-2026-45321 affecting TanStack, where attackers published malicious versions containing credential-stealing malware to the npm registry under the trusted TanStack identity. This supply chain compromise directly threatens any MSSP using TanStack components and creates immediate client advisory obligations since many client development teams likely use this popular React library.
⚠️Why It Matters for MSSPs
Your RMM tools, client portals, or internal dashboards may contain TanStack components that could harvest credentials from your environment. Client development teams across your accounts almost certainly use TanStack, making this a retention risk if you stay silent while their applications leak credentials.
✅Recommended Action
Audit all internal tools and client environments for TanStack usage within 24 hours. Issue immediate client advisories about the compromised npm packages and provide specific remediation steps. Coordinate with clients to identify and isolate any systems running the malicious versions.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Supply Chain
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.