CVE Tools

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

The Hacker NewsBy The Hacker News

Reported exploitedTanStackGitHub

Our summary

CrowdSec says an attacker used a former employee's GitHub OAuth token to copy about 170 private repositories after the TanStack npm supply-chain attack tracked as CVE-2026-45321. Malicious TanStack npm packages stole developer credentials, and CrowdSec had not yet removed the former employee's GitHub access when the repositories were copied. The archive later published online included private source code, 83 user email addresses, and information on 51 potential investors; CrowdSec says its infrastructure and databases were not accessed and exposed credentials have been rotated.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store