Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2916+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
NEWS

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

A former employee's still-active GitHub token, compromised in May's TanStack npm attack, let a hacker copy 170 of CrowdSec's private repos.

Dylan H.

News Desk

September 19, 2026
3 min read

A Token That Should Have Been Revoked

French cybersecurity firm CrowdSec disclosed on September 18, 2026 that an attacker copied roughly 170 of its private GitHub repositories back on May 22, 2026 — using a GitHub OAuth token belonging to a former employee whose access had never been revoked. CrowdSec said it kept the ex-employee's GitHub access open "so he could finish some work," while his other systems access had already been removed. That partial offboarding is why the intrusion left no trace in the logs CrowdSec was actively monitoring.


The Root Compromise: TanStack's May npm Attack

The former employee's laptop was infected through the TanStack npm supply chain attack, tracked as CVE-2026-45321. On May 11, 2026, attackers published malicious versions of 42 TanStack npm packages containing code that stole credentials directly from developer machines — GitHub tokens, SSH keys, and cloud credentials among them. CrowdSec has not specified which malicious package version reached the employee's device or exactly when.

Eleven days later, on May 22, the attacker used the stolen token to copy the 170 repositories. CrowdSec removed the former employee's GitHub access on May 25 — three days after the theft, but with no indication at the time that anything had happened.


What Was Taken

The stolen archive, roughly four months old at the time of discovery, included:

  • 170 private GitHub repositories — source code for CrowdSec's web console, internal data science scripts, automation tooling, and the consensus algorithm that determines when an IP address gets added to CrowdSec's crowdsourced blocklist
  • 83 user email addresses pulled from a product research database
  • 51 potential investor records from a 2020-era system, including names and investment context

Timeline

DateEvent
May 11, 2026Malicious TanStack npm packages published (CVE-2026-45321)
May 22, 2026Attacker copies 170 repos using the ex-employee's still-valid GitHub token
May 25, 2026CrowdSec revokes the former employee's GitHub access
August 17, 2026Unauthorized attempt to use an exposed AWS SNS credential detected
September 16, 2026Stolen code archive posted on an online forum
September 16–17, 2026CrowdSec rotates all exposed credentials
September 18, 2026CrowdSec publishes its full incident report

Response and Broader Fallout

CrowdSec has since rotated all exposed credentials, deployed endpoint protection software on developer machines with access to sensitive code, and begun notifying the users whose emails were exposed, with outreach to affected investors and regulators planned. CEO Philippe Humeau personally apologized to investors in the company's disclosure.

CrowdSec is not the only organization caught up in the TanStack compromise: Mistral AI reported a compromised developer device, and OpenAI disclosed that two employee devices were affected, giving attackers access to a limited set of its internal code repositories.

Sources

  • The Hacker News — CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
#Supply Chain#npm#TanStack#GitHub#Credential Theft

Related Articles

GitHub Breached — Employee Device Hack Led to Exfiltration

GitHub is investigating unauthorized access to thousands of internal repositories after an employee device was compromised through the TanStack npm supply...

6 min read

Grafana GitHub Breach Exposes Source Code via TanStack npm

Grafana Labs confirms its GitHub environment was breached through the TanStack npm supply chain attack, exposing public and private source code...

6 min read

Grafana Says Codebase and Other Data Stolen via TanStack

Grafana confirmed attackers stole internal source code and data after a GitHub token compromised in the TanStack npm supply chain attack was never...

4 min read
Back to all News