Home / Sep 20, 2026 / Story
0
#8 The Hacker News general September 19, 2026 at 07:14 UTC

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

By [email protected] (The Hacker News)

AI Summary

CrowdSec disclosed on September 18 that an attacker copied approximately 170 private GitHub repositories on May 22 by leveraging the still-active GitHub account of a recently departed employee whose laptop was compromised in the TanStack npm supply chain attack — in which malicious npm package versions stole developer credentials. The incident illustrates compounding risk from supply chain attacks combined with inadequate offboarding procedures.

Relevance score: 80.0/100

# More from September 20