Back to feed

CrowdSec says TanStack npm attack led to copy of 170 private GitHub repos

2 min
CrowdSec says TanStack npm attack led to copy of 170 private GitHub repos

This digest was compiled by AI from multiple sources — links to the originals are below.

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of a former employee, CrowdSec said on September 18. The French security company said the employee's laptop was compromised in the May supply chain attack on TanStack npm packages. The stolen code appeared on an online forum on September 16, along with email addresses of 83 users and 51 potential investors.

Key Facts

  • CrowdSec said an attacker copied about 170 of its private GitHub repositories on May 22 using the account of a former employee.
  • The employee's laptop was compromised in the May supply chain attack on TanStack npm packages, tracked as CVE-2026-45321.
  • The stolen code appeared on an online forum on September 16, along with email addresses of 83 CrowdSec users and 51 potential investors from 2020.
  • CrowdSec removed the former employee's account from its GitHub organization on May 25, three days after the copy and months before learning of the leak.
  • The same TanStack attack also affected Mistral AI and OpenAI, with unauthorized access to a limited set of OpenAI's internal code repositories.

The TanStack Compromise

On May 11, 84 malicious versions of 42 TanStack npm packages were published, tracked as CVE-2026-45321. Installing one of those versions ran code that stole credentials from the machine, including GitHub tokens, SSH keys, and cloud credentials, according to TanStack's advisory. CrowdSec says the copy was made 11 days later with a GitHub OAuth token from the former employee's account, which the company had kept open so he could finish some work. The token left no trace in the GitHub logs CrowdSec could check and no longer existed when the company learned of the leak. GitHub support later traced the token's history and confirmed CrowdSec's suspicion that TanStack was the source.

Leaked Code Contents

The leaked code comes from CrowdSec's private repositories, not its public open-source Security Engine. According to CrowdSec, the code includes its web console, data science scripts and models, automation scripts, and the consensus algorithm that determines which IP addresses are added to blocklists. The leak also revealed the thresholds the consensus algorithm uses, such as how many detections it requires before adding an IP address to the blocklist, which had not been public before. CrowdSec says the code is almost four months old and has changed a lot since.

1 source

Time · lag behind first