CrowdSec Says GitHub Repos Stolen After TanStack Attack
CrowdSec says a token from the May TanStack npm compromise was used to copy private GitHub source; reports differ on scale and leaks.
CrowdSec said attackers tied to the May 2026 TanStack npm supply-chain attack, attributed to TeamPCP (also tracked as UNC6780) and associated with Shai-Hulud, used a stolen GitHub credential linked to a former employee to copy private source code. GBHackers says the group backdoored 42 TanStack packages on May 11 and cloned repositories on May 22, while SecurityWeek says TeamPCP published 84 malicious artifacts across 42 packages and compromised an API key. The reports disagree on scale: GBHackers and Dark Reading describe about 170 repositories or 170 private repositories, whereas SecurityWeek says roughly 300 repositories were compromised, including about 170 private ones holding SaaS console, AWS, connector, and automation code. GBHackers reports that console and detection code, emails for 83 users, 2020 investor contacts, and one restricted AWS SNS credential later tested on August 17 were exposed, while SecurityWeek says no customer credentials or data leaked. CrowdSec said production infrastructure, customer databases, CI/CD pipelines, and open-source code were not altered, that potentially affected tokens and credentials were rotated, and, according to GBHackers, that the exposure was publicly disclosed on September 16.
- TeamPCP, also tracked as UNC6780, is linked to the May 2026 TanStack npm compromise and Shai-Hulud credential-harvesting malware.
- GBHackers says the group backdoored 42 TanStack packages on May 11; SecurityWeek says TeamPCP published 84 malicious artifacts across 42 packages and compromised an API key.
- A former employee's GitHub OAuth token was used on May 22 to clone CrowdSec repositories; Dark Reading says the token was taken from that employee's computer, while GBHackers describes a lingering account.
- Sources disagree on scope: about 170 repositories, or 170 private ones, versus SecurityWeek's roughly 300 repositories including about 170 private ones with SaaS console, AWS, connector, and automation code.
- GBHackers says exposed material included console and detection code, emails for 83 users, 2020 investor contacts, and one restricted AWS SNS credential tested on August 17.
- SecurityWeek says no customer credentials or data were leaked and that CrowdSec rotated all potentially affected tokens and credentials.
- CrowdSec said production infrastructure, customer databases, CI/CD pipelines, and open-source code were not altered; GBHackers says public disclosure was September 16.
Coverage timelineoldest first · each row is one article
- · 6d agoHackers Exploit TanStack Supply Chain Attack to Steal 170 Private CrowdSec Repositories
GBHackers· 73
CrowdSec says TeamPCP cloned about 170 repositories using a GitHub token stolen in the TanStack npm compromise.
- · 5d agoCrowdSec Confirms Source Code Stolen in Supply Chain Attack
SecurityWeek· 58
CrowdSec confirmed attackers stole source code from roughly 300 GitHub repositories via the May 2026 TanStack supply chain attack; no customer data affected.
- · 4d agoShai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data
Dark Reading· 73