Skip to content

Incidents, taken apart.

Real attacks on the Node.js dependency chain: what happened, whether you are affected, what to do now, and how each one worked, one step at a time. Every fact traces to a linked primary source.

  • Ember: a bug in code you trust. Upgrade, and rotate only if you were exposed.
  • Night: a package turned malicious. Whatever installed it is compromised: isolate, then rotate.
  1. The TanStack Start server-function XSS

    • CVE-2026-102989
    • CVSS 9.3
    • Fresh · still developing
    • No exploitation reported

    A link to your own app's server-function endpoint could make your server answer with HTML an attacker chose, and run it as whoever clicked. Disclosed on 30 September 2026. This is how it worked, layer by layer, and what to do now.

    Code bugDisclosed

  2. The TanStack npm compromise

    • CVE-2026-45321
    • CVSS 9.6
    • Malicious versions
    • CISA KEV · 2026-05-27

    A pull request that was never merged got TanStack's own release pipeline to publish malware, with valid provenance. This is the chain, one trust boundary at a time, and what to do if you installed it.

    Malicious packagePublished to npm

  3. React2Shell

    • CVE-2025-55182
    • CVSS 10.0
    • Exploited in the wild
    • CISA KEV · 2025-12-05

    One unauthenticated HTTP request could run code on any server using React Server Components. This is how it worked, one layer at a time, and what to do about it.

    Code bugDisclosed

  4. Shai-Hulud, the npm worm

    • No CVE
    • Malware advisory per package
    • Malicious versions
    • Waves · Sep and Nov 2025

    Install an infected package and it stole your secrets, then used your own npm token to infect the packages you maintain. Every victim became the next publisher. This is the loop, both waves of it, and what to do if it ran on your machine.

    Malicious packageFirst worm publish

  5. The chalk and debug npm compromise

    • 19 packages
    • Weekly downloads 2B+
    • Malicious versions
    • CVE-2025-59144 (debug)

    One look-alike “update your 2FA” email handed an attacker a maintainer's npm account. Nineteen tiny packages under almost every JavaScript project shipped a payload that stayed quiet on servers and rewrote wallet addresses in users' browsers.

    Malicious packagePublished to npm

  6. The Next.js middleware bypass

    • CVE-2025-29927
    • CVSS 9.1
    • Self-hosted apps exposed
    • Not in CISA KEV

    Next.js trusted an internal header on requests from the internet. Any client could add it, and self-hosted apps skipped their middleware, login checks included. This is how one request walked past the gate.

    Code bugDisclosed