CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CrowdSec, a French security company, disclosed on September 18 that an attacker copied roughly 170 of its private GitHub repositories on May 22. The breach was carried out using the account of an employee who had just left the company, but whose GitHub access had not been revoked.
The company says the employee's laptop was compromised in May, and it connects the incident to the TanStack npm attack as the initial vector. CrowdSec did not reveal the breach until months later, on September 18.
The incident underscores two recurring problems: the danger of leaving access active after an employee departs, and the wide-reaching impact of supply-chain attacks that target popular open-source packages.
Sources · 2
More in Security & Privacy
WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.
Google Fined €403 Million by Irish DPC Over Location Data
The penalty targets Google's GDPR breaches in handling user location data and includes a six-month compliance order.