discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

CrowdSec reports an attack that led to the copying of 170 of its private GitHub repositories, including credentials and investor information.

By Swati Khandelwal·Sep 19·thehackernews.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
Image: thehackernews.com

CrowdSec identifies a supply chain attack on TanStack's npm packages that led to the copying of 170 of its private GitHub repositories, including sensitive data.

Why it matters

This incident highlights the risks of supply chain attacks and the importance of securing npm packages and GitHub repositories to protect sensitive data.

A company called TanStack made some bad software, and someone used their account to copy some of this company's private files. This copy had people's email addresses and some other private information.

Analysis

{"heading_1":"Supply Chain Attack Details","paragraph_1":"CrowdSec removed the former employee's account from its GitHub organization on May 25, 2026, three days after the copy and months before it learned of the leak.","paragraph_2":"CrowdSec's data science team kept the 83 exposed email addresses to study how people used the product, and the company says it will contact those users.","paragraph_3":"CrowdSec says it will report the leak to the investors and to the authorities. CEO Philippe Humeau wrote to the investors in the report that 'for this I personally apologize.'","heading_2":"Impact of the Attack","heading_3":"CrowdSec's Response"}

Key points

  • CrowdSec's private GitHub repositories were copied using an employee's account
  • The malicious code contained sensitive information including email addresses and investor details
  • CrowdSec says the account was used only to copy code, and no code was changed
The Upside

The incident highlights the importance of securing software and data, which can help prevent similar attacks in the future.

The Downside

The incident shows that even with security measures in place, there is still a risk of supply chain attacks and data breaches.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecurity-enginedata-breachnpmgithubsupply-chain-attack

Author

Swati Khandelwal

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 19, 2026

Source

thehackernews.com

Share

Topics

security-enginedata-breachnpmgithubsupply-chain-attack

Related

More from this desk

Oct 8·bleepingcomputer.com

Maryland Man Found Guilty of Stealing $53 Million from Decentralized Crypto Exchange Uranium Finance

Maryland man convicted of hacking Uranium Finance, a decentralized crypto exchange, and stealing $53 million in cryptocurrency.

Oct 8·wired.com

The Man Behind a West Bank Telegram Channel Trying to Keep Palestinian Drivers Safe

A Telegram group helps Palestinian drivers navigate checkpoints in the West Bank, where popular navigation apps fail them.

Oct 8·thehackernews.com

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

The U.S. State Department is offering a $10 million reward for information on Zhang Yu, a Chinese national charged in the 2021 HAFNIUM Microsoft Exchange Server attacks.

Oct 8·thehackernews.com

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

The owner of MonsterCloud, Zohar Pinhasi, is accused of defrauding ransomware victims by secretly paying attackers for decryptors while claiming to use proprietary tools. He allegedly charged clients millions more than the ransoms paid.