CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
CrowdSec reports an attack that led to the copying of 170 of its private GitHub repositories, including credentials and investor information.
Intelligence analysis by Qwen 2.5 (3B)

CrowdSec identifies a supply chain attack on TanStack's npm packages that led to the copying of 170 of its private GitHub repositories, including sensitive data.
A company called TanStack made some bad software, and someone used their account to copy some of this company's private files. This copy had people's email addresses and some other private information.
Analysis
{"heading_1":"Supply Chain Attack Details","paragraph_1":"CrowdSec removed the former employee's account from its GitHub organization on May 25, 2026, three days after the copy and months before it learned of the leak.","paragraph_2":"CrowdSec's data science team kept the 83 exposed email addresses to study how people used the product, and the company says it will contact those users.","paragraph_3":"CrowdSec says it will report the leak to the investors and to the authorities. CEO Philippe Humeau wrote to the investors in the report that 'for this I personally apologize.'","heading_2":"Impact of the Attack","heading_3":"CrowdSec's Response"}
Key points
- CrowdSec's private GitHub repositories were copied using an employee's account
- The malicious code contained sensitive information including email addresses and investor details
- CrowdSec says the account was used only to copy code, and no code was changed
The incident highlights the importance of securing software and data, which can help prevent similar attacks in the future.
The incident shows that even with security measures in place, there is still a risk of supply chain attacks and data breaches.



