HackerFeeds

CyberSecurity News

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

The Hacker News
· September 19, 2026

AI summary

CrowdSec reported that an attacker copied around 170 of its private GitHub repositories on May 22. The breach occurred using the account of a former employee whose GitHub access had not been revoked. The employee's laptop was compromised during a supply chain attack on TanStack in May, which involved malicious versions of TanStack's npm packages stealing credentials. The incident was disclosed by CrowdSec on September 18. The attack on TanStack's npm packages led to the compromise of the employee's laptop, ultimately resulting in the theft of CrowdSec's private repositories. CrowdSec's failure to revoke the former employee's GitHub access contributed to the breach.

Read the full article at The Hacker Newsthehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.