AI Weekly Malaysia

Back to items Summaries

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

ID
26270
Status
summarized
Published
19 Sep 2026, 3:14 PM
Fetched
19 Sep 2026, 5:25 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
8.0
Created
19 Sep 2026, 5:25 PM
Tags
Audience
developersvibe_coderssaas_foundersai_ml_learners

What happened

A May 2026 supply chain attack on TanStack's npm packages (CVE-2026-45321) saw 84 malicious versions of 42 packages published that stole GitHub tokens, SSH keys, and cloud credentials from developer machines. CrowdSec reported that a former employee whose laptop was compromised via this attack had his GitHub access left open after departure, allowing an attacker to copy ~170 private repositories on May 22; the code surfaced on a forum September 16. Mistral AI and OpenAI also confirmed developer devices were affected, with OpenAI reporting unauthorized access to internal code repositories.

Why it matters

Two concrete failures here: (1) CrowdSec kept a departed employee's GitHub org access active so he could 'finish some work' — revoke access at departure, not days later. (2) The malicious npm packages stole GitHub OAuth tokens silently, leaving no trace in logs CrowdSec could inspect. If you install TanStack packages or any npm dependency, audit your lockfiles for versions published around May 11, 2026, and rotate any GitHub tokens or SSH keys that existed on machines that installed npm packages in that window.

Discussion angle

The offboarding gap is the actionable lesson: a single retained GitHub OAuth token for a departed employee turned a developer-laptop compromise into a full private source code leak. Compare your own offboarding checklist — do you revoke GitHub org membership, rotate shared secrets, and invalidate OAuth tokens the same day someone leaves?

Top