CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
Overview
On May 22, CrowdSec reported that an attacker accessed and copied around 170 of its private GitHub repositories. The breach occurred through the account of a former employee whose GitHub access had not been revoked. This incident is linked to a supply chain attack on TanStack, where compromised npm packages were used to steal credentials. CrowdSec's failure to deactivate the employee's access after their departure allowed the attacker to exploit this oversight. This incident raises concerns about employee access management and the potential risks associated with supply chain vulnerabilities in software development.
Key Takeaways
- Affected Systems: CrowdSec's private GitHub repositories
- Action Required: Revoking access for former employees and monitoring for unauthorized access.
- Timeline: Disclosed on September 18, 2023
Original Article Summary
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from
Impact
CrowdSec's private GitHub repositories
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Disclosed on September 18, 2023
Remediation
Revoking access for former employees and monitoring for unauthorized access.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Exploit.