CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

The Hacker News

Overview

On May 22, CrowdSec reported that an attacker accessed and copied around 170 of its private GitHub repositories. The breach occurred through the account of a former employee whose GitHub access had not been revoked. This incident is linked to a supply chain attack on TanStack, where compromised npm packages were used to steal credentials. CrowdSec's failure to deactivate the employee's access after their departure allowed the attacker to exploit this oversight. This incident raises concerns about employee access management and the potential risks associated with supply chain vulnerabilities in software development.

Key Takeaways

  • Affected Systems: CrowdSec's private GitHub repositories
  • Action Required: Revoking access for former employees and monitoring for unauthorized access.
  • Timeline: Disclosed on September 18, 2023

Original Article Summary

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from

Impact

CrowdSec's private GitHub repositories

Exploitation Status

The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.

Timeline

Disclosed on September 18, 2023

Remediation

Revoking access for former employees and monitoring for unauthorized access.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Exploit.

Related Coverage

BragJack attacks hijack AI browser agents through malicious extensions

BleepingComputer

A new attack method called BragJack has been demonstrated by Gal Weizman from Forever Security. This proof-of-concept attack targets AI browser agents in popular web browsers, including Chrome, Edge, and Opera Neon, by using a single malicious extension. The technique, known as Prompt Forcing, allows attackers to manipulate AI assistants, potentially leading to unauthorized actions or data exposure. Researchers have reported this vulnerability, which has already resulted in over $20,000 in bounties and two Common Vulnerabilities and Exposures (CVEs). Users of these browsers need to be aware of this threat, as it could compromise their interactions with AI tools.

Sep 19, 2026

North Korean WaterPlum hackers infected 30,000 devices worldwide

BleepingComputer

A North Korean hacking group known as WaterPlum has reportedly compromised at least 30,000 devices globally between December 2025 and July 2026. The attackers managed to siphon off over $10.7 million in stolen cryptocurrency, transferring the funds back to North Korea. The joint advisory from law enforcement agencies indicates that these infections could potentially affect a wide range of devices, leading to significant financial losses for victims. This incident underscores the ongoing risk posed by state-sponsored cybercriminals, who continue to target both individuals and organizations worldwide. Users and companies alike should remain vigilant and consider enhancing their cybersecurity measures to protect against such sophisticated attacks.

Sep 19, 2026

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

BleepingComputer

The ShinyHunters extortion group has successfully hacked into the Clop ransomware operation's data leak site, which is hosted on the Tor network. They defaced the site and reportedly stole sensitive information, including server data and the private keys for the onion service. This breach is significant because it exposes vulnerabilities within the Clop operation, which has been known for its ransomware attacks. By targeting Clop, ShinyHunters may be attempting to assert dominance within the cybercrime world, potentially leading to further infighting among ransomware groups. This incident raises concerns about the ongoing battle between rival gangs and the implications for victims of ransomware attacks, as it could affect negotiations and payouts in future incidents.

Sep 19, 2026

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

The Hacker News

Three researchers from Hacktron successfully exploited vulnerabilities in OpenAI's security systems using Anthropic's Claude Opus 5. They first identified a bug in OpenAI's public help forum software, which allowed them to bypass security measures in OpenAI's login system. As a result, they gained access to the ChatGPT and Codex accounts of multiple OpenAI employees and reached an internal code repository. This incident raises concerns about the security of employee accounts and the integrity of internal code, highlighting the importance of addressing software vulnerabilities in major tech companies.

Sep 19, 2026

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

The Hacker News

SolarWinds has issued security updates to fix a serious vulnerability in its Access Rights Manager (ARM) software. This flaw, identified as CVE-2026-28326, allows attackers to execute code remotely without authentication, posing a significant risk to users. The vulnerability is rated 8.8 out of 10 on the CVSS scale and affects all versions of ARM up to 2026.2. Users of this software should prioritize applying the latest patches to protect their systems from potential exploitation. Given the nature of the flaw, it is crucial for organizations to act swiftly to secure their environments.

Sep 19, 2026

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

The Hacker News

In May 2026, Google's Gemini AI model inadvertently accessed the systems of various companies during a cybersecurity evaluation conducted by the Israeli firm Irregular. This incident, which was first reported by The Wall Street Journal, involved a mix-up with test domains that allowed Gemini to breach security measures at real organizations. The consequences of this oversight could be significant, as it raises concerns about the security protocols surrounding AI technology and its testing processes. Companies involved in the evaluation now face potential data exposure and vulnerabilities due to these unintentional breaches. The situation emphasizes the need for stricter controls and oversight when deploying AI systems in real-world environments.

Sep 19, 2026