CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
- ID
- 26270
- Status
- summarized
- Published
- 19 Sep 2026, 3:14 PM
- Fetched
- 19 Sep 2026, 5:25 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 8.0
- Created
- 19 Sep 2026, 5:25 PM
- Tags
- Audience
- developersvibe_coderssaas_foundersai_ml_learners
What happened
A May 2026 supply chain attack on TanStack's npm packages (CVE-2026-45321) saw 84 malicious versions of 42 packages published that stole GitHub tokens, SSH keys, and cloud credentials from developer machines. CrowdSec reported that a former employee whose laptop was compromised via this attack had his GitHub access left open after departure, allowing an attacker to copy ~170 private repositories on May 22; the code surfaced on a forum September 16. Mistral AI and OpenAI also confirmed developer devices were affected, with OpenAI reporting unauthorized access to internal code repositories.
Why it matters
Two concrete failures here: (1) CrowdSec kept a departed employee's GitHub org access active so he could 'finish some work' — revoke access at departure, not days later. (2) The malicious npm packages stole GitHub OAuth tokens silently, leaving no trace in logs CrowdSec could inspect. If you install TanStack packages or any npm dependency, audit your lockfiles for versions published around May 11, 2026, and rotate any GitHub tokens or SSH keys that existed on machines that installed npm packages in that window.
Discussion angle
The offboarding gap is the actionable lesson: a single retained GitHub OAuth token for a departed employee turned a developer-laptop compromise into a full private source code leak. Compare your own offboarding checklist — do you revoke GitHub org membership, rotate shared secrets, and invalidate OAuth tokens the same day someone leaves?