npm
Malicioustanstack-virtual-core@9999.0.2
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 9:42 AM UTC
OSV ID
MAL-2025-41275
Ecosystem
npm
Summary
The OpenSSF Package Analysis project identified 'tanstack-virtual-core' @ 9999.0.2 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Source: ossf-package-analysis (b38d98c47aceac75b944aff9d0df30a563d89aaa076329820aa58b119e010448)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.