logo

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

ID: 29bbc462-6a27-55e7-9c9e-dee6131e33a4

STIX ID: report--29bbc462-6a27-55e7-9c9e-dee6131e33a4

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

...
...

CrowdSec disclosed that a malicious TanStack npm supply-chain compromise (CVE-2026-45321) infected a developer device and allowed attackers to steal a GitHub OAuth token; on May 22, 2026 the token was used to copy 170 private repositories (including source code and a consensus algorithm) and extract 83 user emails and 51 investor records, with the stolen archive posted online in September 2026 and subsequent credential rotation and remediation performed by CrowdSec.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.