CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

Summary

CrowdSec reported that an attacker accessed and copied approximately 170 of its private GitHub repositories on May 22. The breach occurred using the GitHub account of a former employee, whose access was not immediately revoked. CrowdSec attributes the compromise to credentials stolen during a supply chain attack on TanStack's npm packages earlier that month.

IFF Assessment

FOE

This incident represents a significant security lapse where private code repositories were accessed, indicating a threat to intellectual property and potentially sensitive information.

Defender Context

This incident highlights the critical importance of immediate access revocation for departing employees and robust security measures against supply chain attacks. Defenders should prioritize credential management, monitor for unusual access patterns to code repositories, and implement strong controls around third-party software dependencies.

Read Full Story →