What it is
Supply-chain malware is different from a normal dependency bug: the dangerous action can happen during installation, before the application ever starts. For @tanstack/arktype-adapter, the repo evidence that matters most is whether a project resolves to one of the malicious published versions.
How it happens
The TanStack and GitHub advisories list two malicious published versions of `@tanstack/arktype-adapter`: 1.166.12 and 1.166.15. Malicious npm releases usually do their damage from an install script, so the code runs the moment `npm install` pulls the version, on a laptop or in CI, before your app is ever built.
What an attacker gets
If either malicious version was installed on a developer workstation or in CI, treat every credential that install process could read as exposed: npm and GitHub tokens, cloud keys, and environment secrets. Clean up the package, rebuild caches and images, and review where those credentials were used.
// what fixvibe reports
What FixVibe reports
Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.
How to fix it
Upgrade @tanstack/arktype-adapter to 1.166.16 or a newer clean release, or remove it if unused. Regenerate the active lockfile from a trusted registry state, rebuild CI images, Docker layers, devcontainers, and dependency caches, then rotate install-time credentials if either malicious version was ever installed.
