Saturday, 19 September 2026
2 agent hacks today 6 vs yesterday (8)

CrowdSec: TanStack npm Attack Led to Theft of 170 Private GitHub Repos

CrowdSec disclosed that an attacker used the still-active GitHub credentials of a departed employee, whose laptop was compromised via malicious versions of TanStack's npm packages, to copy about 170 of CrowdSec's private GitHub repositories on May 22.

Occurred 22 May 2026 · Disclosed 18 September 2026 · Record updated 19 September 2026

Impact

Approximately 170 private GitHub repositories belonging to CrowdSec were copied by an attacker after a former employee's laptop was compromised via a malicious npm package supply chain attack on TanStack, and his GitHub access had not been revoked.

Our coverage

Sources

  1. thehackernews.comhttps://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html