CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
ID: 29bbc462-6a27-55e7-9c9e-dee6131e33a4
STIX ID: report--29bbc462-6a27-55e7-9c9e-dee6131e33a4
Feed Name: CosmicBytez Labs
Threat Score
CrowdSec disclosed that a malicious TanStack npm supply-chain compromise (CVE-2026-45321) infected a developer device and allowed attackers to steal a GitHub OAuth token; on May 22, 2026 the token was used to copy 170 private repositories (including source code and a consensus algorithm) and extract 83 user emails and 51 investor records, with the stolen archive posted online in September 2026 and subsequent credential rotation and remediation performed by CrowdSec.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
