Signal
Critical vulnerabilities and malware found in GuardDog and @tanstack/* packages
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-05-11 14:43 UTCUpdated 2026-05-12 00:12 UTC
github
cveexploitsmalwaresecurity_toolingincident_response
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (1 domains)domains are deduped. counts indicate coverage, not truth.1 top source shown
limited source diversity in top sources
Overview
Recent GitHub advisories reveal multiple security issues affecting GuardDog and @tanstack/* packages.
Entities
GitHubGuardDog@tanstack/*
Score total
0.73
Momentum 24h
3
Posts
3
Origins
1
Source types
1
Duplicate ratio
0%
Why now
- The advisories were published recently in May 2026, indicating active threats.
- Developers and organizations relying on these tools must urgently assess and remediate.
- The critical severity of some issues demands immediate attention to prevent exploitation.
Why it matters
- These vulnerabilities enable attackers to steal sensitive credentials and tokens, risking unauthorized access.
- Malware in widely used packages threatens cloud infrastructure and developer environments.
- Prompt awareness and patching are critical to mitigate these high-impact security risks.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
- GuardDog has a terminal escape injection vulnerability due to unsanitized scan output
- GuardDog remote project scanning has an SSRF vulnerability leading to GitHub token exfiltration
- Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
How sources frame it
- GitHub Advisories: neutral
This briefing consolidates recent GitHub advisories on GuardDog and @tanstack/* packages, highlighting critical vulnerabilities and malware risks to developer security.
All evidence
All evidence
Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
github_advisories · github.com · 2026-05-12 00:12 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 1Origin domains: 1Duplicates: -
Showing 1 / 0
Top publishers (this list)
- github_advisories (1)
Top origin domains (this list)
- github.com (1)