Back to all news
Security

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

The Hacker News·September 19, 2026·1 min read
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left. The French security company kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, where malicious npm packages stole credentials.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store