TanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories
Attackers used an OAuth token stolen in the TanStack npm supply chain attack to clone 170 private CrowdSec GitHub repositories, later leaked on a forum.
CrowdSec disclosed that attackers copied about 170 private GitHub repositories using the OAuth token of a former employee whose account was compromised in the TanStack npm supply chain attack (CVE-2026-45321). The compromise chained an unsafe pull_request_target workflow, GitHub Actions cache poisoning, and OIDC token extraction to publish 84 malicious releases across 42 @tanstack packages that harvested GitHub, npm, cloud, Kubernetes, Vault, and SSH credentials. The repositories were cloned from a Toronto IP on May 22 and the theft surfaced on September 16 when source code appeared on a cybercrime forum. Exposed data included emails of 83 users (<0.05% of 150,000), details on 51 potential investors, and an AWS SNS credential that was tested once.