Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CrowdSec’s GitHub Repositories Exposed in TanStack Attack

CrowdSec’s GitHub Repositories Exposed in TanStack Attack

Posted on September 19, 2026 By CWS

An unauthorized individual accessed approximately 170 private GitHub repositories belonging to CrowdSec on May 22. This breach was facilitated using the account of a recently departed employee, CrowdSec disclosed on September 18.

Incident Details and Initial Response

The security firm, based in France, initially retained the former employee’s GitHub access. In May, his laptop was compromised during a supply chain attack involving TanStack’s npm packages, which were altered to pilfer credentials from developers’ systems. The stolen code surfaced on an online forum on September 16, revealing source code alongside the email addresses of 83 users and information about 51 prospective investors from 2020, according to CrowdSec.

CrowdSec confirmed that the account was solely used for code copying. Their infrastructure and databases were unharmed, and the code itself remained unchanged.

Understanding the Vulnerability

The attack’s origins trace back to May 11, when 84 tainted versions of 42 TanStack npm packages were released, linked to CVE-2026-45321. Installing any of these versions triggered credential theft, including GitHub tokens and SSH keys, as per TanStack’s advisory.

Eleven days post-release, the repositories were copied using a GitHub OAuth token from the former employee’s account. Despite the copy occurring three days before his access was revoked, CrowdSec only discovered the breach months later. No suspicious activity was detected in their AWS systems due to preemptive access revocations.

The token, now non-existent, left no trace in GitHub logs. GitHub support later confirmed TanStack as the breach’s source. CrowdSec did not specify which malicious package affected the former employee’s device, nor did the report include GitHub’s findings.

Impact and Future Implications

The breach affected not only CrowdSec but also other companies like Mistral AI and OpenAI, whose employees’ devices were similarly compromised, granting unauthorized access to select internal code repositories.

The leaked archive contained sensitive components from CrowdSec’s private repositories, not their public Security Engine. This includes web console code, data science scripts, and a consensus algorithm for blocklisting malicious IPs. The leaked code, however, is outdated and has undergone significant changes since.

Despite concerns, CrowdSec asserts that the blocklist cannot be easily manipulated. The attacker would need substantial resources across trusted networks to achieve this. CrowdSec has also swiftly rotated the exposed AWS SNS credentials and enhanced security measures by implementing endpoint protection software on developers’ machines.

Looking ahead, CrowdSec plans to notify affected users and investors and report the incident to relevant authorities. CEO Philippe Humeau personally apologized to investors for the breach. The company’s proactive measures aim to prevent future occurrences.

The Hacker News Tags:credential theft, CrowdSec, CVE-2026-45321, Cybersecurity, data leak, data protection, developer security, GitHub, npm attack, online forum, private repositories, security breach, supply chain attack, TanStack

Post navigation

Previous Post: CISA Identifies Critical Linux Kernel Vulnerabilities
Next Post: Orkes Conductor Platform Vulnerability Exploited in the Wild

Related Posts

Security Flaw in Vertex AI Risks Google Cloud Data Security Flaw in Vertex AI Risks Google Cloud Data The Hacker News
Ex-CIA Analyst Sentenced to 37 Months for Leaking Top Secret National Defense Documents Ex-CIA Analyst Sentenced to 37 Months for Leaking Top Secret National Defense Documents The Hacker News
Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell The Hacker News
Microsoft Addresses Active Windows Zero-Day Vulnerability Microsoft Addresses Active Windows Zero-Day Vulnerability The Hacker News
Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell The Hacker News
MirrorFace Targets Japan and Taiwan with ROAMINGMOUSE and Upgraded ANEL Malware MirrorFace Targets Japan and Taiwan with ROAMINGMOUSE and Upgraded ANEL Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Orkes Conductor Platform Vulnerability Exploited in the Wild
  • CrowdSec’s GitHub Repositories Exposed in TanStack Attack
  • CISA Identifies Critical Linux Kernel Vulnerabilities
  • Critical WordPress Flaw Allows Remote Code Execution
  • BragJack Exploit Threatens AI Agents on Major Browsers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Orkes Conductor Platform Vulnerability Exploited in the Wild
  • CrowdSec’s GitHub Repositories Exposed in TanStack Attack
  • CISA Identifies Critical Linux Kernel Vulnerabilities
  • Critical WordPress Flaw Allows Remote Code Execution
  • BragJack Exploit Threatens AI Agents on Major Browsers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark