#8
The Hacker News
general
September 19, 2026 at 07:14 UTC
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
By [email protected] (The Hacker News)
AI Summary
CrowdSec disclosed on September 18 that an attacker copied approximately 170 private GitHub repositories on May 22 by leveraging the still-active GitHub account of a recently departed employee whose laptop was compromised in the TanStack npm supply chain attack — in which malicious npm package versions stole developer credentials. The incident illustrates compounding risk from supply chain attacks combined with inadequate offboarding procedures.
Relevance score: 80.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →