Summary
Togoder Security scanned the npm package @tanstack/query-core@5.90.12 on Oct 4, 2026. An AI review of 116 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| build/legacy/chunk-PXG64RU4.js | safe | No malicious patterns detected; the file only contains standard private field access helper functions generated by TypeScript. |
| build/legacy/focusManager.cjs | safe | No malicious patterns detected; the code is a standard focus manager implementation with no data exfiltration, credential access, obfuscation, or suspicious behaviors. |
| build/legacy/focusManager.js | safe | No malicious patterns detected; the code is a standard focus manager for React Query's legacy build. |
| build/legacy/hydration.cjs | safe | No malicious patterns detected; the file contains standard hydration/dehydration logic from TanStack Query with no data exfiltration, credential harvesting, obfuscated code, dynamic execution, or suspicious network/process activity. |
| build/legacy/hydration.js | safe | No malicious patterns detected |
| build/legacy/index.cjs | safe | No malicious patterns detected; this is a standard CommonJS bundle re-exporting internal modules with no network, filesystem, or process activity. |
| build/legacy/index.js | safe | No malicious patterns detected |
| build/legacy/infiniteQueryBehavior.cjs | safe | This is a legitimate TanStack Query infinite query behavior implementation with no malicious patterns; it only implements client-side pagination logic and signal handling. |
| build/legacy/infiniteQueryBehavior.js | safe | No malicious patterns detected; the code is a legitimate implementation of infinite query behavior for TanStack Query. |
| build/legacy/infiniteQueryObserver.cjs | safe | No malicious patterns detected; the file contains standard bundled JavaScript exports for TanStack Query's InfiniteQueryObserver with only benign module system helpers and class definition. |
| build/legacy/infiniteQueryObserver.js | safe | No malicious patterns detected |
| build/legacy/mutation.cjs | safe | No malicious patterns detected; the file contains standard JavaScript utilities for a TanStack Query mutation class with no network, filesystem, credential, or code-execution risks. |
| build/legacy/mutation.js | safe | No malicious patterns detected; the code is a legitimate mutation state manager for the TanStack Query library with no exfiltration, credential harvesting, obfuscation, or suspicious runtime behavior. |
| build/legacy/mutationCache.cjs | safe | No malicious patterns detected; the code is a standard compiled CommonJS build artifact of a mutation cache utility with no network, filesystem, process, or dynamic execution activity. |
| build/legacy/mutationCache.js | safe | No malicious patterns detected; the code is a standard implementation of a mutation cache from the TanStack Query library. |
| build/legacy/mutationObserver.cjs | safe | No malicious patterns detected; this is a standard build artifact for a MutationObserver class from the TanStack Query library with no obfuscation, network activity, or credential harvesting. |
| build/legacy/mutationObserver.js | safe | This is a standard mutation observer implementation from TanStack Query with no malicious patterns, network calls, credential access, or dynamic code execution. |
| build/legacy/notifyManager.cjs | safe | No malicious patterns detected; the code is a standard notification manager with batching and scheduling utilities from React Query. |
| build/legacy/notifyManager.js | safe | No malicious patterns detected |
| build/legacy/onlineManager.cjs | safe | The file contains standard compiler-generated helpers and an online/offline status manager using browser event listeners, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, process spawning, or suspicious network activity. |
| build/legacy/onlineManager.js | safe | No malicious patterns detected; the code is a standard online/offline manager that listens to browser events and notifies subscribers. |
| build/legacy/queriesObserver.cjs | safe | No malicious patterns detected; the file is a standard compiled CommonJS module for TanStack Query's QueriesObserver with only benign helper boilerplate and no network, filesystem, process, or dynamic execution activity. |
| build/legacy/queriesObserver.js | safe | No malicious patterns detected; this is a standard TanStack Query QueriesObserver module with no external exfiltration, dynamic execution, or suspicious behavior. |
| build/legacy/query.cjs | safe | No malicious patterns detected; the code is a standard build artifact for TanStack Query's core query logic, using only relative imports and no network, filesystem, process, or dynamic code execution. |
| build/legacy/query.js | safe | This is a legitimate TanStack Query library file with no malicious patterns, network exfiltration, credential harvesting, obfuscation, or process spawning. |
Show 91 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| build/legacy/queryCache.cjs | safe | No malicious patterns detected; the file contains standard CommonJS build output for a query cache implementation with no network, filesystem, process execution, or obfuscation red flags. |
| build/legacy/queryCache.js | safe | This is a standard QueryCache implementation from TanStack Query with no malicious patterns, network calls, file system access, or code execution. |
| build/legacy/queryClient.cjs | safe | No malicious patterns detected; the file is a legitimate build artifact of TanStack Query's QueryClient with no exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| build/legacy/queryClient.js | safe | No malicious patterns detected; the code is a standard TanStack Query QueryClient implementation with no exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| build/legacy/queryObserver.cjs | safe | No malicious patterns detected; this is a legitimate TanStack Query QueryObserver module with standard utility and class definitions. |
| build/legacy/queryObserver.js | safe | This is a legitimate TanStack Query QueryObserver module with no malicious patterns detected. |
| build/legacy/removable.cjs | safe | No malicious patterns detected |
| build/legacy/removable.js | safe | No malicious patterns detected |
| build/legacy/retryer.cjs | safe | No malicious patterns detected |
| build/legacy/retryer.js | safe | No malicious patterns detected; this is a legitimate retry logic module from TanStack Query with no data exfiltration, credential harvesting, dynamic code execution, or suspicious network/file operations. |
| build/legacy/streamedQuery.cjs | safe | No malicious patterns detected; the code is a standard CommonJS build artifact for a streamed query utility with no network, filesystem, or dynamic execution risks. |
| build/legacy/streamedQuery.js | safe | No malicious patterns detected; the code implements a legitimate streamed query utility for a data-fetching library. |
| build/legacy/subscribable.cjs | safe | No malicious patterns detected |
| build/legacy/subscribable.js | safe | The code is a simple event subscription class with no malicious patterns such as network requests, environment access, code execution, or file system manipulation. |
| build/legacy/thenable.cjs | safe | No malicious patterns detected; the code is a standard thenable utility with no network, filesystem, process, or obfuscation concerns. |
| build/legacy/thenable.js | safe | The code implements a pending thenable utility with no malicious patterns, external calls, or sensitive data access. |
| build/legacy/timeoutManager.cjs | safe | No malicious patterns detected; the code is a benign timeout manager utility with standard build wrapper functions. |
| build/legacy/timeoutManager.js | safe | No malicious patterns detected |
| build/legacy/types.cjs | safe | No malicious patterns detected |
| build/legacy/types.js | safe | No malicious patterns detected |
| build/legacy/utils.cjs | safe | This is a legitimate TanStack Query utility module with no malicious patterns detected; it only contains standard helper functions for query matching, hashing, and data manipulation. |
| build/legacy/utils.js | safe | No malicious patterns detected; the file contains standard utility functions for TanStack Query. |
| build/modern/focusManager.cjs | safe | No malicious patterns detected; the code is a standard focus manager using visibilitychange event listeners with no data exfiltration, credential harvesting, or dynamic code execution. |
| build/modern/focusManager.js | safe | No malicious patterns detected |
| build/modern/hydration.cjs | safe | No malicious patterns detected; the code is a standard TanStack Query hydration utility with no network, filesystem, process, or obfuscated behavior. |
| build/modern/hydration.js | safe | No malicious patterns detected; this is standard TanStack Query hydration serialization logic with no data exfiltration, credential harvesting, code execution, or network/file/process abuse. |
| build/modern/index.cjs | safe | No malicious patterns detected; this is a standard CommonJS bundle re-exporting internal modules with no network, filesystem, or process activity. |
| build/modern/index.js | safe | This is a standard re-export module from TanStack Query that only imports and exports library components with no malicious patterns detected. |
| build/modern/infiniteQueryBehavior.cjs | safe | This is a legitimate TanStack Query infinite query behavior module with no malicious patterns, network calls, credential harvesting, or obfuscated code. |
| build/modern/infiniteQueryBehavior.js | safe | No malicious patterns detected; the code implements infinite query pagination logic for a data-fetching library without any exfiltration, credential harvesting, obfuscation, or process execution. |
| build/modern/infiniteQueryObserver.cjs | safe | No malicious patterns detected; this is a standard TanStack Query InfiniteQueryObserver build file with only expected imports and class logic. |
| build/modern/infiniteQueryObserver.js | safe | Cleared by Jev triage; no further analysis needed |
| build/modern/mutation.cjs | safe | No malicious patterns detected |
| build/modern/mutation.js | safe | No malicious patterns detected |
| build/modern/mutationCache.cjs | safe | The code is a standard mutation cache implementation for a JavaScript library, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| build/modern/mutationCache.js | safe | No malicious patterns detected; the code is a standard TanStack Query MutationCache implementation with no network, filesystem, process, or dynamic execution activity. |
| build/modern/mutationObserver.cjs | safe | This is a transpiled TanStack Query MutationObserver module with no malicious patterns, network calls, credential harvesting, or dynamic code execution. |
| build/modern/mutationObserver.js | safe | This is a standard TanStack Query MutationObserver implementation with no malicious patterns, network calls, code execution, or file system access. |
| build/modern/notifyManager.cjs | safe | No malicious patterns detected; the code is a standard notification manager with batching and scheduling utilities from React Query. |
| build/modern/notifyManager.js | safe | Cleared by Jev triage; no further analysis needed |
| build/modern/onlineManager.cjs | safe | This is a standard browser online/offline status manager from TanStack Query; it only registers online/offline event listeners and contains no malicious patterns. |
| build/modern/onlineManager.js | safe | This is a legitimate online/offline status manager from TanStack Query with no malicious patterns; it only adds standard browser event listeners. |
| build/modern/queriesObserver.cjs | safe | No malicious patterns detected; the code is a standard CommonJS build of a TanStack Query QueriesObserver with no network, filesystem, process, or dynamic code execution behavior. |
| build/modern/queriesObserver.js | safe | No malicious patterns detected; the code is a standard TanStack Query observer implementation with no network, credential, or process-related red flags. |
| build/modern/query.cjs | safe | No malicious patterns detected |
| build/modern/query.js | safe | No malicious patterns detected; this is standard TanStack Query source code with no exfiltration, credential harvesting, obfuscation, or suspicious network/process activity. |
| build/modern/queryCache.cjs | safe | No malicious patterns detected; this is a standard query cache implementation from TanStack Query. |
| build/modern/queryCache.js | safe | Cleared by Jev triage; no further analysis needed |
| build/modern/queryClient.cjs | safe | This is a legitimate TanStack Query QueryClient build artifact with standard class implementation and no malicious patterns, network exfiltration, credential harvesting, obfuscated code, or shell execution. |
| build/modern/queryClient.js | safe | Cleared by Jev triage; no further analysis needed |
| build/modern/queryObserver.cjs | safe | No malicious patterns detected; the file is a standard TanStack Query QueryObserver implementation with no data exfiltration, credential harvesting, obfuscation, dynamic execution, or suspicious network/process activity. |
| build/modern/queryObserver.js | safe | No malicious patterns detected |
| build/modern/removable.cjs | safe | No malicious patterns detected |
| build/modern/removable.js | safe | Cleared by Jev triage; no further analysis needed |
| build/modern/retryer.cjs | safe | No malicious patterns detected; this is a standard retry utility from TanStack Query with no exfiltration, credential harvesting, obfuscation, or process execution. |
| build/modern/retryer.js | safe | Cleared by Jev triage; no further analysis needed |
| build/modern/streamedQuery.cjs | safe | No malicious patterns detected; the code is a standard CommonJS build artifact for a streamed query utility with no network, filesystem, or dynamic execution risks. |
| build/modern/streamedQuery.js | safe | No malicious patterns detected; the code is a benign streaming query utility for a data fetching library. |
| build/modern/subscribable.cjs | safe | No malicious patterns detected |
| build/modern/subscribable.js | safe | No malicious patterns detected; this is a simple, benign event subscription utility class with no network, filesystem, process, credential, or dynamic code execution behavior. |
| build/modern/thenable.cjs | safe | No malicious patterns detected; the code implements standard thenable/promise utilities with no network, filesystem, process, or dynamic execution activity. |
| build/modern/thenable.js | safe | No malicious patterns detected; the code only implements a synchronous thenable wrapper and sync resolution helper without external communication, credential access, dynamic code execution, or process spawning. |
| build/modern/timeoutManager.cjs | safe | The code is a legitimate timeout manager utility that wraps global timer functions and does not contain any malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning. |
| build/modern/timeoutManager.js | safe | No malicious patterns detected; the code is a straightforward timeout manager with no data exfiltration, credential harvesting, dynamic code execution, filesystem manipulation, or other red flags. |
| build/modern/types.cjs | safe | No malicious patterns detected |
| build/modern/types.js | safe | The file only defines and exports three Symbol constants with no executable or suspicious behavior. |
| build/modern/utils.cjs | safe | No malicious patterns detected |
| build/modern/utils.js | safe | No malicious patterns detected |
| src/focusManager.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/hydration.ts | safe | No malicious patterns detected; this is a standard React Query data dehydration/hydration module with no external network calls, credential access, dynamic code execution, or process spawning. |
| src/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/infiniteQueryBehavior.ts | safe | No malicious patterns detected |
| src/infiniteQueryObserver.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/mutation.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/mutationCache.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/mutationObserver.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/notifyManager.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/onlineManager.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/queriesObserver.ts | safe | No malicious patterns detected in src/queriesObserver.ts; the code is a legitimate TanStack Query observer implementation with no data exfiltration, credential harvesting, obfuscation, or process execution. |
| src/query.ts | safe | This is a standard TanStack Query core module with no malicious patterns detected. |
| src/queryCache.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/queryClient.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/queryObserver.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/removable.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/retryer.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/streamedQuery.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/subscribable.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/thenable.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/timeoutManager.ts | safe | The code is a legitimate timeout manager implementation for TanStack Query, with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or backdoor mechanisms detected. |
| src/types.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils.ts | safe | No malicious patterns detected; the code is standard TanStack Query utility functions with no exfiltration, credential harvesting, obfuscation, or process execution. |
Affected version ranges
None of the 2 scanned versions of @tanstack/query-core are flagged high or critical. The latest scanned version, 5.104.1, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 5.104.1 | No issues | 1 | 5.104.1 | |
| 5.101.2 โ 5.103.2 | Not scanned | 2 | >=5.101.2 <=5.103.2 | |
| 5.90.12 | No issues | 1 | 5.90.12 | |
| 5.50.1 | Not scanned | 1 | 5.50.1 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @tanstack/query-core
Frequently asked questions
Is @tanstack/query-core safe to use?
Our AI source review of @tanstack/query-core@5.90.12 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @tanstack/query-core contain malware?
No malware was identified in @tanstack/query-core@5.90.12 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @tanstack/query-core checked?
Togoder Security downloaded the published npm package and had an AI model read its 116 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @tanstack/query-core together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @tanstack/query-core@5.90.12, cost nothing.