Signal

Critical vulnerabilities and malware found in GuardDog and @tanstack/* packages

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-05-11 14:43 UTCUpdated 2026-05-12 00:12 UTC
github
cveexploitsmalwaresecurity_toolingincident_response
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (1 domains)domains are deduped. counts indicate coverage, not truth.
1 top source shown
limited source diversity in top sources
Overview

Recent GitHub advisories reveal multiple security issues affecting GuardDog and @tanstack/* packages.

Entities
GitHubGuardDog@tanstack/*
Score total
0.73
Momentum 24h
3
Posts
3
Origins
1
Source types
1
Duplicate ratio
0%
Why now
  • The advisories were published recently in May 2026, indicating active threats.
  • Developers and organizations relying on these tools must urgently assess and remediate.
  • The critical severity of some issues demands immediate attention to prevent exploitation.
Why it matters
  • These vulnerabilities enable attackers to steal sensitive credentials and tokens, risking unauthorized access.
  • Malware in widely used packages threatens cloud infrastructure and developer environments.
  • Prompt awareness and patching are critical to mitigate these high-impact security risks.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • GuardDog has a terminal escape injection vulnerability due to unsanitized scan output
  • GuardDog remote project scanning has an SSRF vulnerability leading to GitHub token exfiltration
  • Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
How sources frame it
  • GitHub Advisories: neutral
This briefing consolidates recent GitHub advisories on GuardDog and @tanstack/* packages, highlighting critical vulnerabilities and malware risks to developer security.
All evidence
All evidence
Show filters & breakdown
Posts loaded: 0Publishers: 1Origin domains: 1Duplicates: -
Showing 1 / 0
Top publishers (this list)
  • github_advisories (1)
Top origin domains (this list)
  • github.com (1)