INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

TanStack npm Attack Exposes 170 Private GitHub Repositories

| 2026-09-21 10:55 CRITICAL MEDIUM DATA BREACH SUPPLY CHAIN
Executive Summary
AI-generated
A series of high-profile cyber attacks has been reported in recent weeks, with multiple organizations falling victim to sophisticated tactics. The TanStack supply chain attack in May 2026 is believed to be the root cause of several subsequent breaches, including a data breach at Revolut that compromised 680 high-profile accounts and $3 million in ransom. Meanwhile, Brevo's supply chain attack injected malware into over 100,000 websites, while Rust Supply Chain Attack was linked to North Korean hackers. Additionally, Gyazo suffered a massive data breach compromising 23 records, and CrowdSec confirmed the theft of source code from its GitHub repositories. The attacks are thought to be connected through their use of TanStack packages and malicious artifacts, with TeamPCP identified as the primary threat actor behind these incidents.
Technical Mitigations AI-generated
• Implementing a robust access control system to limit GitHub repository access to authorized personnel, including revoking access for employees who have left the company. • Regularly auditing and monitoring code repositories for potential security vulnerabilities and exploiting the short exploitation window of supply chain attacks like TanStack's npm attack. • Rotating all potentially affected tokens and credentials immediately after a suspected data breach or supply chain attack.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
TeamPCPTeamPCP CVE-2026-45321CVE-2026-45321
Target & Sectors
FR
technologytechnology
Incident Timeline
‎September 16 and 17
Threat actors successfully exploited exposed credentials to steal the source code of a company.
‎May 2026
Threat actors used a TanStack package to inject malware into 100,000 websites.
tactic Data Breach
organisation TanStack
threat_actor TeamPCP
general_metric 84 malicious artifacts
general_metric 42 TanStack packages
target_region France
data_breach 680 Profile Accounts
financial $3 Ransom
organisation Gyazo Data Breach
data_breach 23 Records Compromised
organisation AWS
organisation API
‎May 11
Threat actors published 84 malicious versions of 42 TanStack npm packages on May 11.
general_metric 84 malicious artifacts
general_metric 42 TanStack packages
‎May 22
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left.
general_metric 170 private ones
‎May 25, three days
The CrowdSec developer removed his account from the GitHub organization three days before it discovered stolen source code.
‎August 17, a month
Threat actors attempted to use the stolen source code on August 17, a month before it was publicly posted.
‎2026/09/14
The French outfit's GitHub repositories were compromised in May 2026, resulting in the theft of its source code.
target_region France
‎September 16
Threat actors posted stolen source code on an online forum on September 16.
‎September 18
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left.
general_metric 170 private ones
organisation Account Changed
‎2026/09/21
CrowdSec's open-source Security Engine was compromised through a TanStack npm attack, resulting in the theft of approximately 300 private and public repositories' source code.
organisation TanStack
organisation CrowdSec
organisation CrowdSec Confirms Source Code Stolen
organisation AWS
organisation API
victims 83 CrowdSec users
organisation SSH
organisation Mistral AI
organisation OpenAI
organisation IP
organisation SNS
victims 150,000 users
‎2026/09/30
Threat actors used a GitHub OAuth token from the former employee's account to create and steal a copy of source code 11 days after the original incident.
organisation GitHub
Tactical Metrics
Metrics
data_breach
680
Profile Accounts
Metrics
financial
3,000,000
Ransom
Metrics
data_breach
23,000,000
Records Compromised
Metrics
victims
83
Crowdsec Users
Metrics
victims
150,000
Users
Intelligence Sources