The OpenSearch Project has sustained a security incident involving an external actor gaining force-push permissions within the project's CI infrastructure to embed malicious packages into four release versions of @opensearch-project/opensearch. Users are instructed to immediately take actions recommended in the Remediation section of this advisory.
Package: @opensearch-project/opensearch
| Version | Published (UTC) | Published (America/New_York) |
|---|---|---|
| 3.5.3 | 2026-05-12T00:47:39Z | May 11, 2026, 8:47:39 PM EDT |
| 3.6.2 | 2026-05-12T00:29:34Z | May 11, 2026, 8:29:34 PM EDT |
| 3.7.0 | 2026-05-12T00:42:29Z | May 11, 2026, 8:42:29 PM EDT |
| 3.8.0 | 2026-05-12T00:43:54Z | May 11, 2026, 8:43:54 PM EDT |
Any computer that has these package versions installed or updated between 00:00 UTC 12 May 2026 (8:00 PM EDT 11 May 2026) and 10:00 UTC 12 May 2026 (6:00 AM EDT 12 May 2026) should be considered fully compromised. Steps should immediately be taken to prevent further compromise.
GHSA-g7cv-rxg3-hmpx https://github.com/TanStack/router/issues/7383
{
"cwe_ids": [
"CWE-506"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-19T14:35:05Z",
"nvd_published_at": null,
"severity": "CRITICAL"
}