Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Ed Sheeran thought fans didn’t want artists to be politically engaged. He’s finding out how wrong he was | Jason Okundaye

    September 19, 2026

    Before-and-after images show effects of rain in drought-hit England and Wales | UK weather

    September 19, 2026

    Inside the secret race to become NATO’s next top general – POLITICO

    September 19, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Ed Sheeran thought fans didn’t want artists to be politically engaged. He’s finding out how wrong he was | Jason Okundaye
    • Before-and-after images show effects of rain in drought-hit England and Wales | UK weather
    • Inside the secret race to become NATO’s next top general – POLITICO
    • Reform UK activists squabble over Farage’s plan for £72m donations | Party funding
    • Join the WIRED World Fair in Miami on November 4
    • Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
    • Banks Now Account for Nearly 1 in 4 EU MiCA Crypto Providers
    • Here’s how Germany can defend its democracy. Banning the AfD isn’t the answer | Timothy Garton Ash
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 19
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 19, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An attacker copied about 170 of CrowdSec’s private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.

    The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May’s supply chain attack on TanStack, in which malicious versions of TanStack’s npm packages stole credentials from developers’ machines.

    The code appeared on an online forum on September 16. Along with the source code, it contained the email addresses of 83 CrowdSec users and the names, email addresses, and investment context of 51 potential investors from 2020, the company said.

    CrowdSec says the account was used only to copy code, that its infrastructure and databases were not accessed, and that no code was changed.

    How the Code Was Taken

    On May 11, 84 malicious versions of 42 TanStack npm packages were published. The compromise is tracked as CVE-2026-45321. Installing one of those versions ran code that stole credentials from the machine, including GitHub tokens, SSH keys, and cloud credentials, according to TanStack’s advisory.

    The company says the copy was made 11 days later with a GitHub OAuth token from the former employee’s account. The company had kept his access so he could finish some work.

    Cybersecurity

    CrowdSec removed his account from its GitHub organization on May 25, three days after the copy and months before it learned of the leak. His other access had already been removed, which the company says explains why it saw no suspicious activity in its AWS systems.

    The token left no trace in the GitHub logs it could check and no longer existed when it learned of the leak. It says GitHub support then traced the token’s history and confirmed its suspicion that TanStack was the source.

    CrowdSec did not say which malicious package reached the former employee’s laptop or when, and its report does not include GitHub’s own findings. It says its developers’ machines were checked and came back clean.

    The same attack also reached other companies. Mistral AI said a developer device was involved in its case, and OpenAI said two employee devices were affected, with unauthorized access to a limited set of its internal code repositories.

    What the Archive Held

    CrowdSec’s open-source Security Engine detects attacks on servers, and users who share their detections receive a shared blocklist of malicious IP addresses. The leaked code comes from the company’s private repositories, not this public engine.

    According to the company, the code includes its web console, data science scripts and models, automation scripts, and the consensus algorithm that determines which IP addresses are added to the blocklists.

    It says the code is almost four months old and has changed a lot since.

    CrowdSec says the leak also revealed the thresholds the consensus algorithm uses, such as how many detections it requires before adding an IP address to the blocklist. These had not been public before.

    As far as it knows, the blocklist still cannot be poisoned, meaning tricked into blocking a harmless IP address. It says an attacker would need tens of detections from tens of trusted engines across tens of separate networks, at great cost. CrowdSec also says it can change the thresholds, as it often does.

    According to the company, the only usable credential in the leak was for AWS’s SNS notification service, and it could only publish messages to one topic. Someone tried to use it on August 17, a month before the code was posted, but got no further. Other tokens in the code had already been rotated or could not be used from the internet, as far as the company knows.

    CrowdSec says it has about 150,000 users. Its data science team kept the 83 exposed email addresses to study how people used the product, and the company says it will contact those users.

    The investors’ details came from a 2020 system that CrowdSec says was never meant to be public. The company says it will report the leak to the investors and to the authorities. CEO Philippe Humeau wrote to the investors in the report that “for this I personally apologize.”

    Cybersecurity

    The affected company rotated the exposed credentials on September 16 and 17. It did not require endpoint protection software on developers’ machines at the time, but it now runs such software on the laptops of staff who work with its code or systems.

    Neither CrowdSec’s report nor its first statement asks users to take any action.

    How CrowdSec’s Account Changed

    CrowdSec’s September 18 report differs from its first statement, published a day earlier. In that statement, CrowdSec said “No client data, login/password, name, organization, or anything else was leaked,” and that the impact was limited to the company.

    The first statement also named the TanStack compromise as the very likely source of the leak. It said a component used inside CrowdSec in May appeared to have been backdoored to steal an API key that could read the private code.

    The September 18 report says none of the malicious TanStack versions were found in CrowdSec’s code, and points instead to the former employee’s account. It also lists the investors’ names, which the first statement said had not leaked, along with the 83 users’ email addresses.

    attack Copy CrowdSec GitHub led npm private Repositories TanStack
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

    NightmareStresser DDoS Service Disrupted in International Operation

    Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

    Zcash targets November upgrade to make private payments up to three times faster

    Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

    New Check Point flaw lets hackers execute code with root privileges

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Ed Sheeran thought fans didn’t want artists to be politically engaged. He’s finding out how wrong he was | Jason Okundaye

    September 19, 2026

    Before-and-after images show effects of rain in drought-hit England and Wales | UK weather

    September 19, 2026

    Inside the secret race to become NATO’s next top general – POLITICO

    September 19, 2026

    Reform UK activists squabble over Farage’s plan for £72m donations | Party funding

    September 19, 2026
    Latest Posts

    Texas deputy used 83K Flock cameras to find woman who had abortion. Was it a welfare check, as he claimed?

    August 4, 2026

    Trump’s Seabed Mining Order Is an Ecological and Political Disaster

    August 4, 2026

    ExxonMobil picks Sercel technology to support operations offshore Guyana

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Ed Sheeran thought fans didn’t want artists to be politically engaged. He’s finding out how wrong he was | Jason Okundaye

    September 19, 2026

    Before-and-after images show effects of rain in drought-hit England and Wales | UK weather

    September 19, 2026

    Inside the secret race to become NATO’s next top general – POLITICO

    September 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.