CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
thehackernews.com Sep 19, 2026

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

AI-summarised brief · reviewed before publication

CrowdSec disclosed that an ex‑employee’s GitHub account, still active after his departure, was used to copy approximately 170 private repositories on May 22. The breach stemmed from a supply‑chain attack on TanStack’s npm packages, which stole credentials from developers’ machines. The copied code included sensitive project files and personal data of 83 users and 51 investors. CrowdSec confirmed no infrastructure was accessed, removed the account on May 25, and has since rotated exposed credentials.

💡 Why It Matters

  • · The incident exposes how third‑party package vulnerabilities can compromise internal codebases and personal data, underscoring the need for strict access controls and continuous monitoring of developer environments.