IncidentsCrowdSec says npm supply chain attack exposed 170 repositories
The French security firm says an attacker used a departed employee's still-active GitHub account to copy about 170 private repositories in May.
19 Sept 2026
CrowdSec disclosed that an attacker used the still-active GitHub credentials of a departed employee, whose laptop was compromised via malicious versions of TanStack's npm packages, to copy about 170 of CrowdSec's private GitHub repositories on May 22.
Occurred 22 May 2026 · Disclosed 18 September 2026 · Record updated 19 September 2026
Approximately 170 private GitHub repositories belonging to CrowdSec were copied by an attacker after a former employee's laptop was compromised via a malicious npm package supply chain attack on TanStack, and his GitHub access had not been revoked.
IncidentsThe French security firm says an attacker used a departed employee's still-active GitHub account to copy about 170 private repositories in May.
19 Sept 2026