Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit TanStack to Steal GitHub Repositories

Hackers Exploit TanStack to Steal GitHub Repositories

Posted on September 19, 2026 By CWS

TanStack Supply Chain Attack

In a recent cybersecurity incident, CrowdSec revealed that approximately 170 private GitHub repositories were accessed by attackers. This breach occurred following the compromise of a former employee’s account through a supply chain attack on TanStack’s npm packages in May.

The breach, initially undetected, came to light when the stolen source code surfaced on a cybercrime forum on September 16. This incident highlights the persistent threat posed by compromised dependencies, which can exploit developer identities long after the initial infection.

Details of the Security Breach

The root of the attack lies in the CVE-2026-45321 vulnerability affecting TanStack’s Router and Start ecosystem. On May 11, attackers exploited a series of vulnerabilities, including an insecure pull_request_target workflow and GitHub Actions cache poisoning. This allowed them to release 84 malicious versions of 42 @tanstack packages.

These packages contained an obfuscated payload that activated during installation to collect sensitive information such as GitHub and npm tokens, cloud credentials, and SSH keys from affected systems.

Impact on CrowdSec

The compromised GitHub account belonged to a developer who had recently left CrowdSec but still had access to finish ongoing work. On May 22, between 05:52 and 06:01 UTC, the attackers used an OAuth token linked to this account to clone the private repositories from an IP address in Toronto, Canada.

CrowdSec removed the former employee from its GitHub organization on May 25, unaware of the unauthorized access. Clues found in the leaked archive, such as a .git/config file containing a GitHub credential, helped CrowdSec trace the breach back to the TanStack vulnerability.

Response and Recommendations

The stolen data included CrowdSec’s SaaS console, data-science scripts, and other sensitive tools. However, CrowdSec confirmed that no production infrastructure or databases were accessed, and the exposed account was used only for Git fetch operations.

In response, CrowdSec rotated credentials, reviewed cloud and GitHub activities, and increased monitoring. They also implemented additional security measures, such as endpoint detection and response on developer workstations, and enforced stricter controls.

This incident underscores critical lessons for organizations. First, multifactor authentication alone cannot prevent the theft of OAuth tokens from compromised endpoints. Second, delayed detection can lead to the loss of crucial evidence, as GitHub retains audit logs for a limited time.

Organizations should consider affected systems compromised, rotate credentials, and enhance monitoring of cloud and source-control logs. It’s crucial to remove outdated access when employees leave and restrict OAuth applications to mitigate risks.

The breach serves as a stark reminder of the evolving nature of supply chain attacks, which increasingly target identities and trust relationships within software ecosystems.

Cyber Security News Tags:cloud credentials, CrowdSec, Cybercrime, Cybersecurity, data breach, developer security, endpoint protection, GitHub, GitHub security, NPM, OAuth token, repository theft, supply chain attack, TanStack

Post navigation

Previous Post: Researchers Exploit OpenAI Accounts via Security Flaws
Next Post: SolarWinds Fixes Critical ARM Security Flaw

Related Posts

Google AI Incident Highlights Cybersecurity Challenges Google AI Incident Highlights Cybersecurity Challenges Cyber Security News
Claude Mythos Preview Detects 10,000+ Zero-Day Threats Claude Mythos Preview Detects 10,000+ Zero-Day Threats Cyber Security News
Writable File in Lenovo’s Windows Directory Enables a Stealthy AppLocker Bypass Writable File in Lenovo’s Windows Directory Enables a Stealthy AppLocker Bypass Cyber Security News
10 Best VPN Alternatives in 2025 10 Best VPN Alternatives in 2025 Cyber Security News
Critical API Flaw Risks DoD Contractor Data Exposure Critical API Flaw Risks DoD Contractor Data Exposure Cyber Security News
Developers Frustrated by ‘No Server Available’ Message Developers Frustrated by ‘No Server Available’ Message Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SolarWinds Fixes Critical ARM Security Flaw
  • Hackers Exploit TanStack to Steal GitHub Repositories
  • Researchers Exploit OpenAI Accounts via Security Flaws
  • Google AI Incident Highlights Cybersecurity Challenges
  • Google Gemini AI Inadvertently Breaches Real Company Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SolarWinds Fixes Critical ARM Security Flaw
  • Hackers Exploit TanStack to Steal GitHub Repositories
  • Researchers Exploit OpenAI Accounts via Security Flaws
  • Google AI Incident Highlights Cybersecurity Challenges
  • Google Gemini AI Inadvertently Breaches Real Company Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark