Summary
Togoder Security scanned the npm package @tanstack/react-query@5.90.12 on Oct 4, 2026. An AI review of 135 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| build/codemods/src/utils/index.cjs | safe | No malicious patterns detected; this is a benign jscodeshift codemod utility for React Query migrations with no network, filesystem, process, or dynamic execution activity. |
| build/codemods/src/utils/transformers/query-cache-transformer.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/src/utils/transformers/query-client-transformer.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/src/utils/transformers/use-query-like-transformer.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/src/v4/key-transformation.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/src/v4/replace-import-specifier.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/src/v4/utils/replacers/key-replacer.cjs | safe | No malicious patterns detected; the code is a standard jscodeshift codemod for transforming query key expressions without network, filesystem, or execution abuse. |
| build/codemods/src/v5/is-loading/is-loading.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/src/v5/keep-previous-data/keep-previous-data.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/src/v5/keep-previous-data/utils/already-has-placeholder-data-property.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/src/v5/remove-overloads/remove-overloads.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/src/v5/remove-overloads/transformers/filter-aware-usage-transformer.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/src/v5/remove-overloads/transformers/query-fn-aware-usage-transformer.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/src/v5/remove-overloads/utils/index.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/src/v5/remove-overloads/utils/unknown-usage-error.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/src/v5/rename-hydrate/rename-hydrate.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/codemods/src/v5/rename-properties/rename-properties.cjs | safe | Cleared by Jev triage; no further analysis needed |
| build/legacy/HydrationBoundary.cjs | safe | This is a standard TanStack Query React HydrationBoundary component transpiled to CommonJS; no malicious patterns, obfuscation, exfiltration, or dynamic code execution are present. |
| build/legacy/HydrationBoundary.js | safe | No malicious patterns detected |
| build/legacy/IsRestoringProvider.cjs | safe | No malicious patterns detected; this is a standard React context provider shim with no network, filesystem, or process activity. |
| build/legacy/IsRestoringProvider.js | safe | No malicious patterns detected |
| build/legacy/QueryClientProvider.cjs | safe | This is a standard React Query Client Provider module with no malicious patterns detected. |
| build/legacy/QueryClientProvider.js | safe | No malicious patterns detected; the code is a standard React context provider for TanStack Query without any suspicious behavior. |
| build/legacy/QueryErrorResetBoundary.cjs | safe | No malicious patterns detected |
| build/legacy/QueryErrorResetBoundary.js | safe | No malicious patterns detected; the code is a standard React error boundary context implementation with no exfiltration, obfuscation, or dynamic code execution. |
Show 110 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| build/legacy/errorBoundaryUtils.cjs | safe | No malicious patterns detected; the code is a standard compiled React Query error boundary utility with no data exfiltration, obfuscation, or suspicious behavior. |
| build/legacy/errorBoundaryUtils.js | safe | No malicious patterns detected; the code is a legitimate React error boundary utility for TanStack Query. |
| build/legacy/index.cjs | safe | This is a standard CommonJS build artifact for TanStack Query React bindings with no malicious patterns detected. |
| build/legacy/index.js | safe | No malicious patterns detected; this is a standard re-export module for the TanStack React Query library. |
| build/legacy/infiniteQueryOptions.cjs | safe | No malicious patterns detected |
| build/legacy/infiniteQueryOptions.js | safe | No malicious patterns detected |
| build/legacy/mutationOptions.cjs | safe | No malicious patterns detected; the file contains only standard CommonJS export boilerplate and a trivial identity function. |
| build/legacy/mutationOptions.js | safe | The file contains a trivial identity function that returns its input, with no network, filesystem, process, or dynamic execution behavior. |
| build/legacy/queryOptions.cjs | safe | No malicious patterns detected |
| build/legacy/queryOptions.js | safe | No malicious patterns detected |
| build/legacy/suspense.cjs | safe | No malicious patterns detected; this is a standard library build artifact with utility functions for suspense handling. |
| build/legacy/suspense.js | safe | No malicious patterns detected; the code is a legitimate React Query suspense utility with no network, filesystem, or dynamic execution activity. |
| build/legacy/types.cjs | safe | No malicious patterns detected; the file only contains standard TypeScript/ESBuild CommonJS interop helpers and an empty export map. |
| build/legacy/types.js | safe | No malicious patterns detected |
| build/legacy/useBaseQuery.cjs | safe | No malicious patterns detected; the file is a standard TanStack Query React hook with only benign runtime behavior and no data exfiltration, credential harvesting, obfuscated payloads, or process/network abuse. |
| build/legacy/useBaseQuery.js | safe | No malicious patterns detected; the code is a legitimate TanStack Query React hook with no data exfiltration, credential harvesting, obfuscation, or process execution. |
| build/legacy/useInfiniteQuery.cjs | safe | This is a benign CommonJS build artifact of a TanStack Query useInfiniteQuery hook with no malicious patterns detected. |
| build/legacy/useInfiniteQuery.js | safe | No malicious patterns detected |
| build/legacy/useIsFetching.cjs | safe | No malicious patterns detected |
| build/legacy/useIsFetching.js | safe | No malicious patterns detected; the code is a legitimate React hook from TanStack Query for tracking fetching state. |
| build/legacy/useMutation.cjs | safe | This is a standard TanStack Query useMutation React hook build file with no malicious patterns, data exfiltration, or suspicious behavior detected. |
| build/legacy/useMutation.js | safe | No malicious patterns detected |
| build/legacy/useMutationState.cjs | safe | No malicious patterns detected |
| build/legacy/useMutationState.js | safe | No malicious patterns detected |
| build/legacy/usePrefetchInfiniteQuery.cjs | safe | No malicious patterns detected; this is a standard CommonJS build artifact of a TanStack Query hook that only prefetches infinite queries via the local QueryClient. |
| build/legacy/usePrefetchInfiniteQuery.js | safe | No malicious patterns detected; the file is a standard React Query prefetch hook with no suspicious behavior. |
| build/legacy/usePrefetchQuery.cjs | safe | No malicious patterns detected |
| build/legacy/usePrefetchQuery.js | safe | No malicious patterns detected; the code is a standard React Query prefetch hook with no exfiltration, obfuscation, or dynamic execution. |
| build/legacy/useQueries.cjs | safe | No malicious patterns detected; this is a standard TanStack Query React hook module. |
| build/legacy/useQueries.js | safe | No malicious patterns detected; this is a legitimate React hook implementation from TanStack Query's useQueries module. |
| build/legacy/useQuery.cjs | safe | This is a standard TanStack Query React hook build artifact containing only module export boilerplate and a simple delegation to useBaseQuery, with no malicious patterns detected. |
| build/legacy/useQuery.js | safe | No malicious patterns detected |
| build/legacy/useSuspenseInfiniteQuery.cjs | safe | No malicious patterns detected; this is a standard TanStack Query module that wraps useBaseQuery with no network, filesystem, or process access. |
| build/legacy/useSuspenseInfiniteQuery.js | safe | No malicious patterns detected |
| build/legacy/useSuspenseQueries.cjs | safe | No malicious patterns detected |
| build/legacy/useSuspenseQueries.js | safe | No malicious patterns detected; this is a legitimate TanStack Query React hook for suspense-enabled queries. |
| build/legacy/useSuspenseQuery.cjs | safe | No malicious patterns detected; the file is a standard TanStack Query React hook build artifact with no data exfiltration, credential harvesting, obfuscation, or process/network manipulation. |
| build/legacy/useSuspenseQuery.js | safe | No malicious patterns detected |
| build/modern/HydrationBoundary.cjs | safe | This is a standard TanStack Query React HydrationBoundary component transpiled to CommonJS; no malicious patterns, obfuscation, exfiltration, or dynamic code execution are present. |
| build/modern/HydrationBoundary.js | safe | No malicious patterns detected |
| build/modern/IsRestoringProvider.cjs | safe | No malicious patterns detected; this is a standard React context provider shim with no network, filesystem, or process activity. |
| build/modern/IsRestoringProvider.js | safe | No malicious patterns detected |
| build/modern/QueryClientProvider.cjs | safe | This is a standard React Query Client Provider module with no malicious patterns detected. |
| build/modern/QueryClientProvider.js | safe | No malicious patterns detected; the code is a standard React context provider for TanStack Query without any suspicious behavior. |
| build/modern/QueryErrorResetBoundary.cjs | safe | No malicious patterns detected |
| build/modern/QueryErrorResetBoundary.js | safe | No malicious patterns detected; the code is a standard React error boundary context implementation with no exfiltration, obfuscation, or dynamic code execution. |
| build/modern/errorBoundaryUtils.cjs | safe | No malicious patterns detected; the code is a standard compiled React Query error boundary utility with no data exfiltration, obfuscation, or suspicious behavior. |
| build/modern/errorBoundaryUtils.js | safe | No malicious patterns detected; the code is a legitimate React error boundary utility for TanStack Query. |
| build/modern/index.cjs | safe | This is a standard CommonJS build artifact for TanStack Query React bindings with no malicious patterns detected. |
| build/modern/index.js | safe | No malicious patterns detected; this is a standard re-export module for the TanStack React Query library. |
| build/modern/infiniteQueryOptions.cjs | safe | No malicious patterns detected |
| build/modern/infiniteQueryOptions.js | safe | No malicious patterns detected |
| build/modern/mutationOptions.cjs | safe | No malicious patterns detected; the file contains only standard CommonJS export boilerplate and a trivial identity function. |
| build/modern/mutationOptions.js | safe | The file contains a trivial identity function that returns its input, with no network, filesystem, process, or dynamic execution behavior. |
| build/modern/queryOptions.cjs | safe | No malicious patterns detected |
| build/modern/queryOptions.js | safe | No malicious patterns detected |
| build/modern/suspense.cjs | safe | No malicious patterns detected; the code is a standard CommonJS build artifact for React Query suspense utilities with no network, filesystem, credential, or execution-related concerns. |
| build/modern/suspense.js | safe | No malicious patterns detected; the file contains legitimate React suspense utility logic for a query library. |
| build/modern/types.cjs | safe | No malicious patterns detected; the file only contains standard TypeScript/ESBuild CommonJS interop helpers and an empty export map. |
| build/modern/types.js | safe | No malicious patterns detected |
| build/modern/useBaseQuery.cjs | safe | This is a standard TanStack React Query build artifact with no malicious patterns, network calls, credential access, or dynamic code execution. |
| build/modern/useBaseQuery.js | safe | No malicious patterns detected in the provided React hook implementation; it contains standard TanStack Query logic with no data exfiltration, credential harvesting, obfuscation, or shell/process execution. |
| build/modern/useInfiniteQuery.cjs | safe | This is a benign CommonJS build artifact of a TanStack Query useInfiniteQuery hook with no malicious patterns detected. |
| build/modern/useInfiniteQuery.js | safe | No malicious patterns detected |
| build/modern/useIsFetching.cjs | safe | No malicious patterns detected |
| build/modern/useIsFetching.js | safe | No malicious patterns detected; the code is a legitimate React hook from TanStack Query for tracking fetching state. |
| build/modern/useMutation.cjs | safe | This is a standard TanStack Query useMutation React hook build file with no malicious patterns, data exfiltration, or suspicious behavior detected. |
| build/modern/useMutation.js | safe | No malicious patterns detected |
| build/modern/useMutationState.cjs | safe | No malicious patterns detected |
| build/modern/useMutationState.js | safe | No malicious patterns detected |
| build/modern/usePrefetchInfiniteQuery.cjs | safe | No malicious patterns detected; this is a standard CommonJS build artifact of a TanStack Query hook that only prefetches infinite queries via the local QueryClient. |
| build/modern/usePrefetchInfiniteQuery.js | safe | No malicious patterns detected; the file is a standard React Query prefetch hook with no suspicious behavior. |
| build/modern/usePrefetchQuery.cjs | safe | No malicious patterns detected |
| build/modern/usePrefetchQuery.js | safe | No malicious patterns detected; the code is a standard React Query prefetch hook with no exfiltration, obfuscation, or dynamic execution. |
| build/modern/useQueries.cjs | safe | No malicious patterns detected; the file is a standard compiled React hook from TanStack Query with no exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| build/modern/useQueries.js | safe | No malicious patterns detected; the file is a legitimate React hook implementation from TanStack Query with no data exfiltration, credential harvesting, obfuscation, or other security concerns. |
| build/modern/useQuery.cjs | safe | This is a standard TanStack Query React hook build artifact containing only module export boilerplate and a simple delegation to useBaseQuery, with no malicious patterns detected. |
| build/modern/useQuery.js | safe | No malicious patterns detected |
| build/modern/useSuspenseInfiniteQuery.cjs | safe | No malicious patterns detected; this is a standard TanStack Query module that wraps useBaseQuery with no network, filesystem, or process access. |
| build/modern/useSuspenseInfiniteQuery.js | safe | No malicious patterns detected |
| build/modern/useSuspenseQueries.cjs | safe | No malicious patterns detected |
| build/modern/useSuspenseQueries.js | safe | No malicious patterns detected; this is a legitimate TanStack Query React hook for suspense-enabled queries. |
| build/modern/useSuspenseQuery.cjs | safe | No malicious patterns detected; the file is a standard TanStack Query React hook build artifact with no data exfiltration, credential harvesting, obfuscation, or process/network manipulation. |
| build/modern/useSuspenseQuery.js | safe | No malicious patterns detected |
| build/query-codemods/eslint.config.js | safe | Cleared by Jev triage; no further analysis needed |
| build/query-codemods/root.eslint.config.js | safe | Cleared by Jev triage; no further analysis needed |
| build/query-codemods/vite.config.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/HydrationBoundary.tsx | safe | Cleared by Jev triage; no further analysis needed |
| src/IsRestoringProvider.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/QueryClientProvider.tsx | safe | Cleared by Jev triage; no further analysis needed |
| src/QueryErrorResetBoundary.tsx | safe | Cleared by Jev triage; no further analysis needed |
| src/errorBoundaryUtils.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/infiniteQueryOptions.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/mutationOptions.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/queryOptions.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/suspense.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/types.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/useBaseQuery.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/useInfiniteQuery.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/useIsFetching.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/useMutation.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/useMutationState.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/usePrefetchInfiniteQuery.tsx | safe | Cleared by Jev triage; no further analysis needed |
| src/usePrefetchQuery.tsx | safe | No malicious patterns detected; the code is a standard TanStack Query prefetch hook with no network, filesystem, process, or obfuscation concerns. |
| src/useQueries.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/useQuery.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/useSuspenseInfiniteQuery.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/useSuspenseQueries.ts | safe | No malicious patterns detected; the code is a standard TanStack Query hook for suspense queries with only type-level complexity and a development-only console error for skipToken misuse. |
| src/useSuspenseQuery.ts | safe | Cleared by Jev triage; no further analysis needed |
Affected version ranges
None of the 2 scanned versions of @tanstack/react-query are flagged high or critical. The latest scanned version, 5.104.1, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 5.104.1 | No issues | 1 | 5.104.1 | |
| 5.101.2 โ 5.103.2 | Not scanned | 2 | >=5.101.2 <=5.103.2 | |
| 5.90.12 | No issues | 1 | 5.90.12 | |
| 5.50.1 | Not scanned | 1 | 5.50.1 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @tanstack/react-query
Frequently asked questions
Is @tanstack/react-query safe to use?
Our AI source review of @tanstack/react-query@5.90.12 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @tanstack/react-query contain malware?
No malware was identified in @tanstack/react-query@5.90.12 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @tanstack/react-query checked?
Togoder Security downloaded the published npm package and had an AI model read its 135 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @tanstack/react-query together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @tanstack/react-query@5.90.12, cost nothing.