logo

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

ID: 9e5057a4-73dc-54d4-8d11-f848d384e005

STIX ID: report--9e5057a4-73dc-54d4-8d11-f848d384e005

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

Author: [email protected] (The Hacker News)

...
...

CrowdSec disclosed that about 170 private GitHub repositories were copied on May 22 after a former employee's laptop was compromised by malicious TanStack npm package versions (CVE-2026-45321) that stole developer credentials; the leak included source code, 83 user emails, and 51 investor records, though CrowdSec says its infrastructure and databases were not accessed and most exposed credentials were unusable or rotated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.