CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
CrowdSec says the TanStack npm supply chain attack let an attacker copy 170 private GitHub repos via a former employee's retained account.
On May 22 an attacker used a GitHub OAuth token from a former CrowdSec employee whose organization access had been kept active, copying about 170 private repositories containing the web console, data science models, and blocklist consensus algorithm. CrowdSec attributes the access to CVE-2026-45321, the May 11 publication of 84 malicious versions of 42 TanStack npm packages that stole GitHub tokens, SSH keys, and cloud credentials from developer machines. The leaked archive also exposed email addresses of 83 users and names, emails, and investment context of 51 potential investors from 2020. The same campaign affected Mistral AI and OpenAI, and the only usable credential found in the leak, an AWS SNS publish token, saw an attempted misuse on August 17.