logo

TanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories

ID: c1527e7b-37e2-53c1-aefa-b2690c1416d5

STIX ID: report--c1527e7b-37e2-53c1-aefa-b2690c1416d5

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

Author: Guru Baran

...
...

CrowdSec disclosed that attackers leveraged the TanStack npm supply-chain compromise (CVE-2026-45321) to publish malicious package releases that harvested GitHub/npm tokens and cloud credentials; a stolen OAuth token was later used to clone roughly 170 private CrowdSec GitHub repositories on May 22. The leaked archive contained source-code, data-science artifacts, some user and investor contact data, and a limited, active AWS credential; CrowdSec reports no production infrastructure access or modifications but rotated secrets, removed the former employee account, increased monitoring, and recommended rebuilds, credential rotation, dependency pinning, and improved long-term logging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.