BreachFeed
← All incidents
companyCrowdSec
confirmedhighSupply chainFirst reported Sep 19, 2026 · Disclosed Sep 18, 2026

CrowdSec: attacker copied ~170 private GitHub repos after TanStack npm compromise

CrowdSec said on September 18 that an attacker copied about 170 of its private GitHub repositories on May 22 using the still-active account of a departed employee. The company said the employee's laptop was compromised in May's supply chain attack on TanStack, where malicious npm package versions stole credentials.

Members only

The full record: the timeline and 2 linked reports

  • Every update as it happened, with the status at each step
  • Every report behind the record, newest first
  • Alerts the moment CrowdSec — or anything else you track — is hit again

A free account is all it takes — no card, one minute.

CrowdSec: attacker copied ~170 private GitHub repos after TanStack npm compromise · BreachFeed