Skip to content
archivesupply chain · 19 Sep 2026 · 07:14 UTC

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

last 60 dispatches · spectrum

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected