Hackers Exploit TanStack Supply Chain Attack to Steal 170 Private CrowdSec Repositories
CrowdSec says TeamPCP cloned about 170 repositories using a GitHub token stolen in the TanStack npm compromise.
CrowdSec said attackers linked to the May TanStack npm compromise, attributed to TeamPCP (UNC6780), used a stolen GitHub OAuth token from a former employee's lingering account to clone about 170 repositories, including private source. On May 11 the group backdoored 42 TanStack packages with Shai Hulud credential-harvesting malware; the clones occurred on May 22 and were publicly disclosed on September 16. Exposed material included console and detection code, emails for 83 users, 2020 investor contacts, and one restricted AWS SNS credential that an actor tested on August 17. CrowdSec said production infrastructure, customer databases, CI/CD pipelines, and open-source code were not altered.
- TeamPCP, also tracked as UNC6780, backdoored 42 TanStack npm packages with Shai Hulud on May 11.
- A former employee's GitHub OAuth token was used on May 22 to clone about 170 CrowdSec repositories.
- The leak included source code, 83 user emails, 2020 investor contacts, and one limited AWS SNS credential.
- CrowdSec said production systems, customer databases, CI/CD, and open-source code were not modified.
- The exposure was publicly disclosed on September 16, months after the May access.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 23.234.84.102 | ed actor tested the credential on August 17 from IP address 23.234.84.102, attempting AWS GetCallerIdentity and ListTopics requests a |
Full article634 words · extracted from gbhackers.com · click to collapse
Threat actors linked to the TanStack npm supply chain compromise allegedly used a stolen GitHub OAuth token to clone about 170 private CrowdSec repositories, exposing source code, limited contact information, and a restricted AWS notification credential.
CrowdSec stated that the compromise originated from a former employee’s account, which remained in the company’s GitHub organization for legitimate work-transition purposes.
This account was compromised in May. CrowdSec removed it three days after the unauthorized access to the repositories. However, the source-code archive exposure was not publicly disclosed until September 16.
Supply Chain Compromise Led to GitHub Access
According to CrowdSec’s incident analysis, the group TeamPCP, also known as UNC6780, compromised the TanStack npm ecosystem on May 11 by backdooring 42 packages with credential-harvesting malware known as Shai Hulud.
This malware reportedly targeted developer credentials and authentication tokens. An attacker then utilized a GitHub OAuth token associated with the departing employee to clone repositories between 05:52:29 and 06:01:33 UTC on May 22.
The cloned data included more than 130 public repositories along with private projects, totaling roughly 170 repositories. Git metadata in the leaked archive indicated that the repositories were downloaded from an IP address located in Toronto, Canada, with a system timezone set to UTC-4.
CrowdSec attributed the unauthorized GitHub activity to the former employee’s compromised account after GitHub support reconstructed the OAuth token’s lifecycle and provided Git activity for the relevant time period.
The security company emphasized that its production infrastructure, customer databases, CI/CD pipelines, and open-source code were not altered or directly accessed during the incident.

“His account was used solely to perform the Git clones that led to the leak,” CrowdSec said, adding that its investigation found no malicious commits, infrastructure changes, or build-pipeline modifications.
The accessed code included CrowdSec’s SaaS console, data science scripts, automation tools, and the company’s Consensus Algorithm. CrowdSec assessed the leaked console code as context-specific and noted that it did not contain sensitive information. However, they acknowledged that exposing source code can help adversaries identify potential weaknesses more quickly.
CrowdSec explained that its Consensus Algorithm, which determines when to add IP addresses to blocklists, relies on signals from multiple vetted security engines distributed across various autonomous systems.
While the leak may have revealed internal detection thresholds, CrowdSec said it regularly adjusts those thresholds, and manipulating the system would require significant resources.
CrowdSec identified one still-valid AWS Simple Notification Service credential in the archive. The token, named assertible-zapier-sns-sender, was restricted to publishing notifications to a single SNS topic.
An unidentified actor tested the credential on August 17 from IP address 23.234.84.102, attempting AWS GetCallerIdentity and ListTopics requests against development and environment topics. CrowdSec reported that the role’s limited permissions prevented further access or lateral movement.
The leaked archive also contained email addresses belonging to 83 users, less than 0.05% of CrowdSec’s approximately 150,000 users, and information on 51 potential investors from 2020, including names, email addresses, and investment context. CrowdSec said it will notify affected individuals and the appropriate authorities.
CrowdSec rotated credentials, revoked remaining tokens, conducted forensic reviews, and issued public communications within 48 hours of discovering the leak. The company credited GitHub, GitGuardian, Aikido, and Fuites Info for their assistance during the response.
This incident underscores how a compromised developer dependency can extend beyond a single workstation, allowing attackers to harvest credentials and access private source code repositories.
CrowdSec noted that stricter offboarding controls, reduced token exposure, continuous package scrutiny, and faster incident-response processes will be essential to preventing similar breaches in the future.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.