Description
https://nuxt.com had a hardcoded GitHub token in the source code of the page. This token had access to multiple repositories under nuxt, nuxtlabs and nuxt-themes GitHub organizations. A patch in version 1.6.2 fixed the issue.
Recommendation
Update the @nuxtlabs/github-module package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.6.2
- Patched version(s): 1.6.2
References
Related Issues
- Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/vue-start - CVE-2026-45321
- Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/vue-start-client - CVE-2026-45321
- Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/react-router-devtools - CVE-2026-45321
- Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/vue-router - CVE-2026-45321
You might also like:
- Tags:
- npm
- @nuxtlabs/github-module
Anything's wrong? Let us know Last updated on November 12, 2023


