Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-16
2 active CVEs reported via OSV.dev
Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
Malicious code in @tanstack/react-router (npm)
Other Frontend projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for TanStack Router — without relying on volunteer maintainers.
Talk to an Expert →