Skip to content
CrowdSec Breach: 170 Private Repositories Compromised via TanStack npm Attack

CrowdSec Breach: 170 Private Repositories Compromised via TanStack npm Attack

First seen 22 Sep 2026, 22:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 00:57 UTC
  • 170 private GitHub repositories stolen from CrowdSec via a compromised OAuth token.
  • Attack linked to the TanStack npm supply chain attack, exploiting malicious npm packages.
  • No infrastructure compromise reported; sensitive user data also exposed.

On May 22, 2026, threat actors exploited a compromised OAuth token from a former CrowdSec employee's machine to steal 170 private GitHub repositories. The breach was linked to the TanStack npm supply chain attack, where malicious npm packages were used to extract credentials. CrowdSec discovered the leak on September 16, 2026, when source code appeared on an underground forum. The stolen data included source code and sensitive user information, although CrowdSec confirmed that its infrastructure remained secure. The OAuth token used for access was not traceable in GitHub logs, complicating the investigation. CrowdSec had retained the former employee's GitHub access for ongoing work, which contributed to the breach. The company removed the compromised account shortly after the incident but was unaware of the breach until months later. CrowdSec has since conducted an investigation and reported its findings publicly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-11
Malicious npm packages published
84 malicious versions of 42 TanStack npm packages were published, leading to credential theft.
Thehackernews
2026-05-12
CVE-2026-45321 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-22
Repositories copied from CrowdSec
An attacker used a stolen OAuth token to copy 170 private GitHub repositories from CrowdSec.
Darkreading
2026-05-25
Compromised account removed
CrowdSec removed the GitHub account of the former employee three days after the incident.
Thehackernews
2026-09-16
Source code leak discovered
CrowdSec learned of the breach when source code appeared on an underground forum.
Darkreading
2026-09-18
CrowdSec publicly acknowledges breach
CrowdSec confirmed the breach and outlined the details of the attack in a blog post.
Thehackernews

More articles in this cluster (2)

Following this threat?

Track Cl0p, ShinyHunters and Shai-hulud in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed