Darkreading CrowdSec Breach: 170 Private Repositories Compromised via TanStack npm Attack
Article Content
- •170 private GitHub repositories stolen from CrowdSec via a compromised OAuth token.
- •Attack linked to the TanStack npm supply chain attack, exploiting malicious npm packages.
- •No infrastructure compromise reported; sensitive user data also exposed.
On May 22, 2026, threat actors exploited a compromised OAuth token from a former CrowdSec employee's machine to steal 170 private GitHub repositories. The breach was linked to the TanStack npm supply chain attack, where malicious npm packages were used to extract credentials. CrowdSec discovered the leak on September 16, 2026, when source code appeared on an underground forum. The stolen data included source code and sensitive user information, although CrowdSec confirmed that its infrastructure remained secure. The OAuth token used for access was not traceable in GitHub logs, complicating the investigation. CrowdSec had retained the former employee's GitHub access for ongoing work, which contributed to the breach. The company removed the compromised account shortly after the incident but was unaware of the breach until months later. CrowdSec has since conducted an investigation and reported its findings publicly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cl0p, ShinyHunters and Shai-hulud in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cleo Harmony Vulnerability Exploited for Privilege Escalation A newly discovered authentication bypass vulnerability in Cleo Harmony, tracked as CVE-2026-84115, allows remote attackers to escalate privileges by manipulating JWT refresh tokens. The flaw, found in the '/api/connections' function, enables attackers to bypass access controls through crafted HTTP headers. An exploit…