negativeSYS.SOURCE: The Hacker News• 2026-09-19T12:44:54+05:30
CrowdSec Discloses Data Breach via TanStack npm Supply Chain Attack Involving 170 Private GitHub Repositories
A supply chain attack on TanStack's npm packages led to the unauthorized copying of 170 private GitHub repositories belonging to CrowdSec, exposing user email addresses and investor data. The breach occurred through a compromised former employee's GitHub account after malicious code stole credentials from developers' machines.
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.
The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from
*** END OF TRANSMISSION ***