INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
TanStack npm Attack Exposes 170 Private GitHub Repositories
| 2026-09-21 10:55 CRITICAL MEDIUM DATA BREACH SUPPLY CHAIN
Executive Summary
AI-generated
A series of high-profile cyber attacks has been reported in recent weeks, with multiple organizations falling victim to sophisticated tactics. The TanStack supply chain attack in May 2026 is believed to be the root cause of several subsequent breaches, including a data breach at Revolut that compromised 680 high-profile accounts and $3 million in ransom. Meanwhile, Brevo's supply chain attack injected malware into over 100,000 websites, while Rust Supply Chain Attack was linked to North Korean hackers. Additionally, Gyazo suffered a massive data breach compromising 23 records, and CrowdSec confirmed the theft of source code from its GitHub repositories. The attacks are thought to be connected through their use of TanStack packages and malicious artifacts, with TeamPCP identified as the primary threat actor behind these incidents.
Technical Mitigations AI-generated
• Implementing a robust access control system to limit GitHub repository access to authorized personnel, including revoking access for employees who have left the company.
• Regularly auditing and monitoring code repositories for potential security vulnerabilities and exploiting the short exploitation window of supply chain attacks like TanStack's npm attack.
• Rotating all potentially affected tokens and credentials immediately after a suspected data breach or supply chain attack.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
TeamPCPTeamPCP
CVE-2026-45321CVE-2026-45321
Target & Sectors
FR
technologytechnology
Incident Timeline
September 16 and 17
Threat actors successfully exploited exposed credentials to steal the source code of a company.
May 2026
Threat actors used a TanStack package to inject malware into 100,000 websites.
Click on any entity below to view its context and source!
tactic
Data Breach
The data breach, it explains, was likely a direct result of the May 2026
TanStack supply chain attack
, in which TeamPCP published 84 malicious artifacts across 42 TanStack packages.
organisation
TanStack
The data breach, it explains, was likely a direct result of the May 2026
TanStack supply chain attack
, in which TeamPCP published 84 malicious artifacts across 42 TanStack packages.
threat_actor
TeamPCP
The data breach, it explains, was likely a direct result of the May 2026
TanStack supply chain attack
, in which TeamPCP published 84 malicious artifacts across 42 TanStack packages.
general_metric
84 malicious artifacts
The data breach, it explains, was likely a direct result of the May 2026
TanStack supply chain attack
, in which TeamPCP published 84 malicious artifacts across 42 TanStack packages.
general_metric
42 TanStack packages
The data breach, it explains, was likely a direct result of the May 2026
TanStack supply chain attack
, in which TeamPCP published 84 malicious artifacts across 42 TanStack packages.
target_region
France
Last week, the French outfit learned that source code had been stolen from its GitHub repositories in May 2026.
data_breach
680 Profile Accounts
Related:
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related:
financial
$3 Ransom
Related:
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related:
organisation
Gyazo Data Breach
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Related:
Rust Supply Chain Attack Linked to North Korean Hackers
Related:
23 Million User Records Compromised in Gyazo Data Breach
data_breach
23 Records Compromised
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Related:
Rust Supply Chain Attack Linked to North Korean Hackers
Related:
23 Million User Records Compromised in Gyazo Data Breach
organisation
AWS
“The private part contains the source code for our SaaS console, some AWS Cloud routines, some connectors, and automations,” the company said.
organisation
API
Because CrowdSec used a TanStack package in May, the malware used in the campaign likely compromised an API key that allowed the attackers to read its private codebase.
May 11
Threat actors published 84 malicious versions of 42 TanStack npm packages on May 11.
Click on any entity below to view its context and source!
general_metric
84 malicious artifacts
How the Code Was Taken
On May 11, 84 malicious versions of 42 TanStack npm packages were published.
general_metric
42 TanStack packages
How the Code Was Taken
On May 11, 84 malicious versions of 42 TanStack npm packages were published.
May 22
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left.
Click on any entity below to view its context and source!
general_metric
170 private ones
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.
May 25, three days
The CrowdSec developer removed his account from the GitHub organization three days before it discovered stolen source code.
August 17, a month
Threat actors attempted to use the stolen source code on August 17, a month before it was publicly posted.
2026/09/14
The French outfit's GitHub repositories were compromised in May 2026, resulting in the theft of its source code.
Click on any entity below to view its context and source!
target_region
France
Last week, the French outfit learned that source code had been stolen from its GitHub repositories in May 2026.
September 16
Threat actors posted stolen source code on an online forum on September 16.
September 18
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left.
Click on any entity below to view its context and source!
general_metric
170 private ones
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.
organisation
Account Changed
How CrowdSec's Account Changed
CrowdSec's September 18 report differs from its
first statement
, published a day earlier.
2026/09/21
CrowdSec's open-source Security Engine was compromised through a TanStack npm attack, resulting in the theft of approximately 300 private and public repositories' source code.
Click on any entity below to view its context and source!
organisation
TanStack
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories.
organisation
CrowdSec
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories.
French cybersecurity firm CrowdSec has confirmed that approximately 300 private and public repositories were compromised and source code was stolen from them.
organisation
CrowdSec Confirms Source Code Stolen
CrowdSec Confirms Source Code Stolen in Supply Chain Attack.
organisation
AWS
His other access had already been removed, which the company says explains why it saw no suspicious activity in its AWS systems.
organisation
API
It said a component used inside CrowdSec in May appeared to have been backdoored to steal an API key that could read the private code.
victims
83 CrowdSec users
Along with the source code, it contained the email addresses of 83 CrowdSec users and the names, email addresses, and investment context of 51 potential investors from 2020, the company said.
It also lists the investors' names, which the first statement said had not leaked, along with the 83 users' email addresses.
organisation
SSH
Installing one of those versions ran code that stole credentials from the machine, including GitHub tokens, SSH keys, and cloud credentials, according to
TanStack's advisory
.
organisation
Mistral AI
Mistral AI
said a developer device was involved in its case, and
OpenAI
said two employee devices were affected, with unauthorized access to a limited set of its internal code repositories.
organisation
OpenAI
Mistral AI
said a developer device was involved in its case, and
OpenAI
said two employee devices were affected, with unauthorized access to a limited set of its internal code repositories.
organisation
IP
What the Archive Held
CrowdSec's open-source Security Engine detects attacks on servers, and users who share their detections receive a shared blocklist of malicious IP addresses.
organisation
SNS
According to the company, the only usable credential in the leak was for AWS's SNS notification service, and it could only publish messages to one topic.
victims
150,000 users
CrowdSec says it has about 150,000 users.
2026/09/30
Threat actors used a GitHub OAuth token from the former employee's account to create and steal a copy of source code 11 days after the original incident.
Click on any entity below to view its context and source!
organisation
GitHub
The company says the copy was made 11 days later with a GitHub OAuth token from the former employee's account.
Tactical Metrics
Metrics
data_breach
680
Profile Accounts
Click for context!
Related:
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related:
Metrics
financial
3,000,000
Ransom
Related:
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related:
Metrics
data_breach
23,000,000
Records Compromised
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Related:
Rust Supply Chain Attack Linked to North Korean Hackers
Related:
23 Million User Records Compromised in Gyazo Data Breach
Metrics
victims
83
Crowdsec Users
Along with the source code, it contained the email addresses of 83 CrowdSec users and the names, email addresses, and investment context of 51 potential investors from 2020, the company said.
It also lists the investors' names, which the first statement said had not leaked, along with the 83 users' email addresses.
Metrics
victims
150,000
Users
CrowdSec says it has about 150,000 users.
Intelligence Sources
The Hacker News
2026-09-19
SecurityWeek
2026-09-21
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:06
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
TanStack
entity
12x
timeline
Temporal Reference
May 2026
date
2x
tactic
Cyber Operation Type
Lateral Movement
tactic
Contextual Telemetry
Context Block
18 METRICS
threat actor
APT Group
TeamPCP
actor
general metric
Malicious Artifacts
84
malicious artifacts
general metric
Tanstack Packages
42
tanstack packages
data breach
Profile Accounts
680
profile accounts
financial
Ransom
3,000,000
ransom
source region
Origin Region
DPRK
region
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
data breach
Records Compromised
23,000,000
records compromised
target region
Target Country
France
country
source region
Origin Country
France
country
general metric
Private Repositories
300
private repositories
general metric
Private Ones
170
private ones
vulnerability
Exploited CVE
CVE-2026-45321
cve
victims
Crowdsec Users
83
crowdsec users
general metric
Potential Investors
51
potential investors
victims
Users
150,000
users
general metric
Exposed Email Addresses
83
exposed email addresses
general metric
System
2,020
system
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.