CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
Reported exploitedTanStackGitHubOur summary
CrowdSec says an attacker used a former employee's GitHub OAuth token to copy about 170 private repositories after the TanStack npm supply-chain attack tracked as CVE-2026-45321. Malicious TanStack npm packages stole developer credentials, and CrowdSec had not yet removed the former employee's GitHub access when the repositories were copied. The archive later published online included private source code, 83 user email addresses, and information on 51 potential investors; CrowdSec says its infrastructure and databases were not accessed and exposed credentials have been rotated.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.