CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec’s private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.

The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May’s supply chain attack on TanStack, in which malicious versions of TanStack’s npm packages stole credentials from

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Denmark Requires Oral Defenses for Students’ Written Work to Counter AI Cheating

Denmark Requires Oral Defenses for Students’ Written Work to Counter AI Cheating Source: Hacker News

An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. In July 2025, someone registered a domain that used to belong to a content delivery network.  The CDN

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to