
TanStack npm Supply Chain Hit Copies 170 CrowdSec Private Repos via Stolen GitHub Token
A May 2026 TanStack npm supply chain compromise enabled theft of a CrowdSec engineer's GitHub token, resulting in the copying of 170 private repositories. The leak exposed internal consensus thresholds and limited user data but no active infrastructure access. The case underscores systemic offboarding failures and the downstream reach of npm credential theft.
On May 11, 84 malicious versions of 42 TanStack packages were uploaded under CVE-2026-45321. Execution on developer machines harvested GitHub tokens, SSH keys, and cloud credentials. Eleven days later the token from a recently departed CrowdSec engineer was used to clone private repositories before access was revoked on May 25. No infrastructure changes or database access occurred.
CrowdSec's September 18 disclosure lists the leaked contents as its web console, data science models, automation scripts, and the IP blocklist consensus algorithm with its detection thresholds. The same token theft also touched Mistral AI and OpenAI devices, confirming a multi-target credential harvest rather than an isolated incident. GitHub token logs left no trace; only later support tracing confirmed the TanStack vector.
The incident reveals persistent offboarding gaps across security firms: retained tokens for transitional work created a single point of failure that bypassed AWS monitoring. Leaked consensus thresholds and investor details from 2020 remain low-value for poisoning the shared blocklist, yet they expose operational parameters previously withheld from the 150,000-user community.
CrowdSec has rotated remaining credentials and will notify affected users and investors. Similar token-harvesting campaigns against other npm ecosystems are expected within the next quarter as attackers replicate the low-cost credential exfiltration pattern.
CrowdSec: No blocklist poisoning attempts using leaked thresholds will be observed before December 2026.
Sources (2)
- [1]Primary Source(https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html)
- [2]Supporting Source(https://tanstack.com/blog/security-advisory-2026-05)