hacker-news · Crawled Sep 19, 2026

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

1 CVEs
Read original article ↗

AI Summary

CrowdSec disclosed that approximately 170 of its private GitHub repositories were copied on May 22, 2026, due to a supply chain attack stemming from the compromise of a former employee's laptop via malicious TanStack npm packages. The attacker leveraged a GitHub OAuth token from the former employee's account, which had not been revoked promptly after departure. The breach exposed source code, including internal automation scripts, data science models, and the consensus algorithm used in its blocklist system, as well as sensitive information such as 83 user email addresses and investor details from 2020. The initial compromise is linked to CVE-2026-45321, a supply chain attack on TanStack that stole developer credentials.

AI-extracted · verify before operational use

Extracted Entities 1 found

MITRE ATT&CK TTPs 1 techniques