By Interestana AI Editorial — AI-drafted, human-overseen. How we report
CrowdSec Reports 170 Private GitHub Repos Copied After TanStack Attack

CrowdSec reported on September 18 that an attacker successfully copied approximately 170 of its private GitHub repositories on May 22. The breach occurred through the compromised account of a former employee whose GitHub access had been inadvertently maintained by the French security company. CrowdSec stated that the former employee's laptop was compromised during a supply chain attack targeting TanStack in May. This attack involved malicious versions of TanStack's npm packages, which were designed to steal credentials from users.
The compromised credentials, obtained through the TanStack npm package attack, were subsequently used to access the former employee's GitHub account. CrowdSec indicated that the attacker leveraged this access to exfiltrate the contents of the private repositories. The company has initiated an investigation into the incident and is working to assess the full scope of the data exposure. CrowdSec has also implemented additional security measures to prevent similar incidents in the future, including stricter access control policies and enhanced monitoring of employee accounts.
The TanStack supply chain attack, which CrowdSec fell victim to, involved the distribution of compromised npm packages. These packages, when installed by developers, would execute malicious code designed to steal sensitive information, including authentication tokens and API keys. The attack vector highlights the increasing sophistication of supply chain attacks, which target the software development lifecycle to compromise downstream users. CrowdSec, a collaborative security automation platform, relies heavily on private code repositories for its development and intellectual property, making the theft of these repositories a significant security concern.
CrowdSec has not disclosed the specific nature of the data contained within the 170 private repositories, but it is understood that such repositories typically house proprietary code, internal documentation, and potentially sensitive project details. The company is in the process of notifying affected parties and is providing guidance on how to mitigate potential risks arising from the breach. The incident underscores the critical importance of robust security practices for software supply chains and the need for continuous vigilance against evolving cyber threats. CrowdSec's response includes a review of its internal security protocols and a commitment to strengthening its defenses against future attacks.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.