Summary
Togoder Security scanned the npm package @tanstack/react-query@5.104.1 on Oct 6, 2026. An AI review of 134 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| build/codemods/utils/index.cjs | safe | No malicious patterns detected; this is a benign jscodeshift codemod utility for React Query migrations with no network, filesystem, process, or dynamic execution activity. |
| build/codemods/utils/transformers/query-cache-transformer.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/utils/transformers/query-client-transformer.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/utils/transformers/use-query-like-transformer.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/v4/key-transformation.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/v4/replace-import-specifier.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/v4/utils/replacers/key-replacer.cjs | safe | No malicious patterns detected; the code is a standard jscodeshift codemod for transforming query key expressions without network, filesystem, or execution abuse. |
| build/codemods/v5/is-loading/is-loading.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/v5/keep-previous-data/keep-previous-data.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/v5/keep-previous-data/utils/already-has-placeholder-data-property.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/v5/remove-overloads/remove-overloads.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/v5/remove-overloads/transformers/filter-aware-usage-transformer.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/v5/remove-overloads/transformers/query-fn-aware-usage-transformer.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/v5/remove-overloads/utils/index.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/v5/remove-overloads/utils/unknown-usage-error.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/v5/rename-hydrate/rename-hydrate.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/v5/rename-properties/rename-properties.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/legacy/HydrationBoundary.cjs | safe | No malicious patterns detected; the file is a legitimate TanStack Query HydrationBoundary implementation with standard React and query hydration logic. |
| build/legacy/HydrationBoundary.js | safe | No malicious patterns detected; the code is a legitimate React Query HydrationBoundary implementation using only standard React hooks and internal hydration logic. |
| build/legacy/IsRestoringProvider.cjs | safe | No malicious patterns detected |
| build/legacy/IsRestoringProvider.js | safe | Cleared by Jev triage; no further analysis needed |
| build/legacy/QueryClientProvider.cjs | safe | No malicious patterns detected; this is a standard React context provider implementation from TanStack Query. |
| build/legacy/QueryClientProvider.js | safe | No malicious patterns detected; the file is a legitimate React Query provider implementation with no exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| build/legacy/QueryErrorResetBoundary.cjs | safe | No malicious patterns detected |
| build/legacy/QueryErrorResetBoundary.js | safe | No malicious patterns detected |
Show 109 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| build/legacy/errorBoundaryUtils.cjs | safe | No malicious patterns detected |
| build/legacy/errorBoundaryUtils.js | safe | No malicious patterns detected |
| build/legacy/index.cjs | safe | This is a standard legacy CommonJS build artifact for TanStack React Query that only re-exports APIs from local modules and @tanstack/query-core with no malicious patterns detected. |
| build/legacy/index.js | safe | No malicious patterns detected |
| build/legacy/infiniteQueryOptions.cjs | safe | No malicious patterns detected |
| build/legacy/infiniteQueryOptions.js | safe | No malicious patterns detected |
| build/legacy/mutationOptions.cjs | safe | No malicious patterns detected |
| build/legacy/mutationOptions.js | safe | No malicious patterns detected |
| build/legacy/queryOptions.cjs | safe | No malicious patterns detected |
| build/legacy/queryOptions.js | safe | No malicious patterns detected |
| build/legacy/rolldown-runtime-VH7oDXx4.cjs | safe | No malicious patterns detected |
| build/legacy/suspense.cjs | safe | No malicious patterns detected |
| build/legacy/suspense.js | safe | No malicious patterns detected; the file contains only benign suspense utility logic with no network, filesystem, process, or dynamic code execution activity. |
| build/legacy/types.cjs | safe | No malicious patterns detected |
| build/legacy/types.js | safe | No malicious patterns detected |
| build/legacy/useBaseQuery.cjs | safe | No malicious patterns detected; the code is a standard TanStack Query React hook implementation with no security concerns. |
| build/legacy/useBaseQuery.js | safe | No malicious patterns detected; this is a legitimate TanStack Query React hook with no data exfiltration, credential harvesting, obfuscation, process spawning, or other security red flags. |
| build/legacy/useInfiniteQuery.cjs | safe | No malicious patterns detected |
| build/legacy/useInfiniteQuery.js | safe | No malicious patterns detected; the file is a standard React hook wrapper for TanStack Query's useInfiniteQuery. |
| build/legacy/useIsFetching.cjs | safe | No malicious patterns detected |
| build/legacy/useIsFetching.js | safe | No malicious patterns detected; this is a standard React Query useIsFetching hook that only uses internal library APIs and React hooks with no network, filesystem, or process operations. |
| build/legacy/useMutation.cjs | safe | No malicious patterns detected; the file is a standard TanStack React Query useMutation hook implementation with no exfiltration, obfuscation, process spawning, or filesystem access. |
| build/legacy/useMutation.js | safe | This is a standard TanStack React Query useMutation hook implementation with no malicious patterns detected. |
| build/legacy/useMutationState.cjs | safe | No malicious patterns detected; the file is a legitimate React hook implementation from TanStack Query with only expected requires and no obfuscation, network calls, or process execution. |
| build/legacy/useMutationState.js | safe | No malicious patterns detected |
| build/legacy/usePrefetchInfiniteQuery.cjs | safe | This file contains only legitimate TanStack Query hook implementation with no malicious patterns, network exfiltration, obfuscation, or dynamic code execution. |
| build/legacy/usePrefetchInfiniteQuery.js | safe | This is a standard React Query hook implementation with no malicious patterns, external calls, or suspicious behavior detected. |
| build/legacy/usePrefetchQuery.cjs | safe | The code is a legitimate TanStack Query React hook implementation with no malicious patterns, external data transmission, credential harvesting, or dynamic code execution. |
| build/legacy/usePrefetchQuery.js | safe | No malicious patterns detected |
| build/legacy/useQueries.cjs | safe | This is a legitimate TanStack Query React hook implementation with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution. |
| build/legacy/useQueries.js | safe | No malicious patterns detected; this is a legitimate TanStack React Query hook that only performs in-process query management with no network, filesystem, or process access. |
| build/legacy/useQuery.cjs | safe | No malicious patterns detected |
| build/legacy/useQuery.js | safe | No malicious patterns detected |
| build/legacy/useSuspenseInfiniteQuery.cjs | safe | No malicious patterns detected; this is a standard TanStack React Query hook implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| build/legacy/useSuspenseInfiniteQuery.js | safe | No malicious patterns detected; the file is a standard TanStack Query React hook implementation with only documentation comments, a NODE_ENV console warning, and calls to local modules. |
| build/legacy/useSuspenseQueries.cjs | safe | No malicious patterns detected; the code is a legitimate React Query hook implementation for suspense queries. |
| build/legacy/useSuspenseQueries.js | safe | No malicious patterns detected in the analyzed React suspense hook implementation. |
| build/legacy/useSuspenseQuery.cjs | safe | No malicious patterns detected |
| build/legacy/useSuspenseQuery.js | safe | This is a standard TanStack React Query hook implementation with no malicious patterns, network calls, credential access, dynamic code execution, or process spawning. |
| build/modern/HydrationBoundary.cjs | safe | No malicious patterns detected; the file is a legitimate TanStack Query HydrationBoundary implementation with standard React and query hydration logic. |
| build/modern/HydrationBoundary.js | safe | No malicious patterns detected; the code is a legitimate React Query HydrationBoundary implementation using only standard React hooks and internal hydration logic. |
| build/modern/IsRestoringProvider.cjs | safe | No malicious patterns detected |
| build/modern/IsRestoringProvider.js | safe | Cleared by Jev triage; no further analysis needed |
| build/modern/QueryClientProvider.cjs | safe | No malicious patterns detected; this is a standard React context provider implementation from TanStack Query. |
| build/modern/QueryClientProvider.js | safe | No malicious patterns detected; the file is a legitimate React Query provider implementation with no exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| build/modern/QueryErrorResetBoundary.cjs | safe | No malicious patterns detected |
| build/modern/QueryErrorResetBoundary.js | safe | No malicious patterns detected |
| build/modern/errorBoundaryUtils.cjs | safe | No malicious patterns detected |
| build/modern/errorBoundaryUtils.js | safe | No malicious patterns detected |
| build/modern/index.cjs | safe | This is a standard legacy CommonJS build artifact for TanStack React Query that only re-exports APIs from local modules and @tanstack/query-core with no malicious patterns detected. |
| build/modern/index.js | safe | No malicious patterns detected |
| build/modern/infiniteQueryOptions.cjs | safe | No malicious patterns detected |
| build/modern/infiniteQueryOptions.js | safe | No malicious patterns detected |
| build/modern/mutationOptions.cjs | safe | No malicious patterns detected |
| build/modern/mutationOptions.js | safe | No malicious patterns detected |
| build/modern/queryOptions.cjs | safe | No malicious patterns detected |
| build/modern/queryOptions.js | safe | No malicious patterns detected |
| build/modern/rolldown-runtime-VH7oDXx4.cjs | safe | No malicious patterns detected |
| build/modern/suspense.cjs | safe | No malicious patterns detected; the file contains normal React Query suspense logic with no network, filesystem, process, or dynamic execution activity. |
| build/modern/suspense.js | safe | No malicious patterns detected |
| build/modern/types.cjs | safe | No malicious patterns detected |
| build/modern/types.js | safe | No malicious patterns detected |
| build/modern/useBaseQuery.cjs | safe | No malicious patterns detected; the code is a standard TanStack Query React hook implementation with no security concerns. |
| build/modern/useBaseQuery.js | safe | No malicious patterns detected; this is a legitimate TanStack Query React hook with no data exfiltration, credential harvesting, obfuscation, process spawning, or other security red flags. |
| build/modern/useInfiniteQuery.cjs | safe | No malicious patterns detected |
| build/modern/useInfiniteQuery.js | safe | No malicious patterns detected; the file is a standard React hook wrapper for TanStack Query's useInfiniteQuery. |
| build/modern/useIsFetching.cjs | safe | No malicious patterns detected |
| build/modern/useIsFetching.js | safe | No malicious patterns detected; this is a standard React Query useIsFetching hook that only uses internal library APIs and React hooks with no network, filesystem, or process operations. |
| build/modern/useMutation.cjs | safe | No malicious patterns detected; the file is a standard TanStack React Query useMutation hook implementation with no exfiltration, obfuscation, process spawning, or filesystem access. |
| build/modern/useMutation.js | safe | This is a standard TanStack React Query useMutation hook implementation with no malicious patterns detected. |
| build/modern/useMutationState.cjs | safe | No malicious patterns detected; the file is a legitimate React hook implementation from TanStack Query with only expected requires and no obfuscation, network calls, or process execution. |
| build/modern/useMutationState.js | safe | No malicious patterns detected |
| build/modern/usePrefetchInfiniteQuery.cjs | safe | This file contains only legitimate TanStack Query hook implementation with no malicious patterns, network exfiltration, obfuscation, or dynamic code execution. |
| build/modern/usePrefetchInfiniteQuery.js | safe | This is a standard React Query hook implementation with no malicious patterns, external calls, or suspicious behavior detected. |
| build/modern/usePrefetchQuery.cjs | safe | The code is a legitimate TanStack Query React hook implementation with no malicious patterns, external data transmission, credential harvesting, or dynamic code execution. |
| build/modern/usePrefetchQuery.js | safe | No malicious patterns detected |
| build/modern/useQueries.cjs | safe | This is a legitimate TanStack Query React hook implementation with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution. |
| build/modern/useQueries.js | safe | No malicious patterns detected; this is a legitimate TanStack React Query hook that only performs in-process query management with no network, filesystem, or process access. |
| build/modern/useQuery.cjs | safe | No malicious patterns detected |
| build/modern/useQuery.js | safe | No malicious patterns detected |
| build/modern/useSuspenseInfiniteQuery.cjs | safe | No malicious patterns detected; this is a standard TanStack React Query hook implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| build/modern/useSuspenseInfiniteQuery.js | safe | No malicious patterns detected; the file is a standard TanStack Query React hook implementation with only documentation comments, a NODE_ENV console warning, and calls to local modules. |
| build/modern/useSuspenseQueries.cjs | safe | No malicious patterns detected; the code is a legitimate React Query hook implementation for suspense queries. |
| build/modern/useSuspenseQueries.js | safe | No malicious patterns detected in the analyzed React suspense hook implementation. |
| build/modern/useSuspenseQuery.cjs | safe | No malicious patterns detected |
| build/modern/useSuspenseQuery.js | safe | This is a standard TanStack React Query hook implementation with no malicious patterns, network calls, credential access, dynamic code execution, or process spawning. |
| src/HydrationBoundary.tsx | safe | Cleared by Jev triage; no further analysis needed |
| src/IsRestoringProvider.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/QueryClientProvider.tsx | safe | Cleared by Jev triage; no further analysis needed |
| src/QueryErrorResetBoundary.tsx | safe | Cleared by Jev triage; no further analysis needed |
| src/errorBoundaryUtils.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/infiniteQueryOptions.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/mutationOptions.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/queryOptions.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/suspense.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/types.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/useBaseQuery.ts | safe | No malicious patterns detected |
| src/useInfiniteQuery.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/useIsFetching.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/useMutation.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/useMutationState.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/usePrefetchInfiniteQuery.tsx | safe | No malicious patterns detected; the file is a legitimate React hook that prefetches infinite query data via the TanStack Query client without any network, filesystem, process, or dynamic code execution behavior. |
| src/usePrefetchQuery.tsx | safe | No malicious patterns detected; the code is a straightforward React hook wrapper around TanStack Query's prefetch functionality. |
| src/useQueries.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/useQuery.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/useSuspenseInfiniteQuery.ts | safe | No malicious patterns detected |
| src/useSuspenseQueries.ts | safe | This is a legitimate TanStack React Query hook implementation with no malicious patterns, network exfiltration, process spawning, or dynamic code execution. |
| src/useSuspenseQuery.ts | safe | This is a legitimate React Query Suspense hook implementation with no malicious patterns, obfuscation, network exfiltration, or dangerous code execution. |
Affected version ranges
None of the 2 scanned versions of @tanstack/react-query are flagged high or critical. The latest scanned version, 5.104.1, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 5.104.1 | No issues | 1 | 5.104.1 | |
| 5.101.2 โ 5.103.2 | Not scanned | 2 | >=5.101.2 <=5.103.2 | |
| 5.90.12 | No issues | 1 | 5.90.12 | |
| 5.50.1 | Not scanned | 1 | 5.50.1 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @tanstack/react-query
Frequently asked questions
Is @tanstack/react-query safe to use?
Our AI source review of @tanstack/react-query@5.104.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @tanstack/react-query contain malware?
No malware was identified in @tanstack/react-query@5.104.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @tanstack/react-query checked?
Togoder Security downloaded the published npm package and had an AI model read its 134 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @tanstack/react-query together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @tanstack/react-query@5.104.1, cost nothing.