CrowdSec: TanStack npm Attack Led to Copy of 170 Private GitHub Repos
CrowdSec reported that on May 22 an attacker copied about 170 of its private GitHub repositories. Access was through an account of a recently departed employee whose laptop was compromised in an attack on TanStack npm packages.
- About 170 private CrowdSec repositories copied
- Attack occurred May 22, disclosed September 18
- Used account of departed employee with retained access
- Malicious TanStack npm package versions stole credentials
Read next
Security