CVE Tools
Back to feed
Exploited in the wild TanStack supply-chain GitHub CrowdSec data-breach

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

CrowdSec says an attacker used a former employee's GitHub OAuth token to copy about 170 private repositories after the TanStack npm supply-chain attack tracked as CVE-2026-45321. Malicious TanStack npm packages stole developer credentials, and CrowdSec had not yet removed the former employee's GitHub access when the repositories were copied. The archive later published online included private source code, 83 user email addresses, and information on 51 potential investors; CrowdSec says its infrastructure and databases were not accessed and exposed credentials have been rotated.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store