Tuesday, 22 September 2026

Search
Latent Digest

TECHNOLOGY, TRACKED ACROSS DISCIPLINES

Security & Privacy

CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos

CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.

· 1 min read · 2 sources

CrowdSec, a French security company, disclosed on September 18 that an attacker copied roughly 170 of its private GitHub repositories on May 22. The breach was carried out using the account of an employee who had just left the company, but whose GitHub access had not been revoked.

The company says the employee's laptop was compromised in May, and it connects the incident to the TanStack npm attack as the initial vector. CrowdSec did not reveal the breach until months later, on September 18.

The incident underscores two recurring problems: the danger of leaving access active after an employee departs, and the wide-reaching impact of supply-chain attacks that target popular open-source packages.

Sources · 2

  1. 01CrowdSec Confirms Source Code Stolen in Supply Chain AttackSecurityWeek
  2. 02CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub RepositoriesThe Hacker News

More in Security & Privacy