TanStack NPM Supply Chain Attack Exposes 170 Private CrowdSec GitHub Repositories

CrowdSec has disclosed that a May 2026 compromise tied to the TanStack npm supply-chain incident enabled attackers to clone roughly 170 private GitHub repositories, exposing internal source code and limited sensitive contact data.

The company said the intrusion was traced to a former employee’s GitHub OAuth token, which attackers allegedly obtained through the broader TanStack compromise attributed to TeamPCP, also tracked as UNC6780.

CrowdSec emphasized that its production infrastructure, databases, CI/CD pipelines, and open-source code were not altered or directly compromised.

TanStack NPM Supply Chain Attack

TeamPCP compromised the TanStack npm ecosystem on May 11, backdooring 42 packages with the credential-harvesting malware known as Shai Hulud.

The malicious campaign targeted developer environments for GitHub tokens, cloud credentials, SSH keys, and other secrets.

Between 05:52 UTC and 06:01 UTC on May 22, an attacker used a GitHub OAuth token associated with a recently departed CrowdSec employee to download the contents of approximately 170 private repositories.

Git metadata indicated the activity originated from an IP address geolocated to Toronto, Canada, with a system timezone consistent with UTC-4.

Data Leak Claim
Data Leak Claim (Source: crowdsec)

The attacker later published an archive of CrowdSec repositories on a breach forum on September 16. The archive included more than 130 public repositories, along with private code, SaaS console components, data-science scripts, automation tooling, and internal project material.

CrowdSec said the newest commits in the archive dated to May 22, helping investigators establish the date and scope of the theft.

Forensic analysis found a GitHub remote URL containing an oauth2:gho_ token, confirming that the repository cloning operation relied on a GitHub OAuth credential rather than a direct infrastructure compromise.

CrowdSec initially struggled to identify the token in its audit logs because it had already expired or been revoked before the incident was discovered. GitHub support later helped trace the token lifecycle and provided Git activity records for the relevant timeframe.

The investigation linked the activity to an employee account that remained in the GitHub organization after the employee’s departure. CrowdSec had retained access temporarily to allow the developer to complete outstanding work.

The account was removed from the organization on May 25, three days after the repository-cloning activity.

CrowdSec said further review found no evidence that the attacker committed code, modified repositories, changed CI/CD workflows, or accessed AWS infrastructure.

The former employee’s broader access had already been revoked, limiting the attacker’s ability to pivot beyond GitHub source-code access.

The leaked codebase reportedly contained one active AWS Simple Notification Service (SNS) credential. CrowdSec said the token was narrowly scoped to publishing notifications to a single SNS topic and could not be used to access broader AWS resources.

The credential was tested on August 17 from IP address 23.234.84.102 using GetCallerIdentity and ListTopics requests. CrowdSec stated that the activity did not progress beyond those checks, as the IAM role lacked permissions for wider account access.

The organization also disclosed that the archive contained email addresses for 83 users, representing fewer than 0.05% of its approximately 150,000 users.

It additionally exposed names, email addresses, and investment context involving 51 potential investors from 2020. CrowdSec said it would notify affected individuals and report the matter to relevant authorities.

CrowdSec said existing controls, including privilege separation, 2FA, scoped cloud permissions, secrets management, code scanning, package-age controls, and logging, limited the breach impact.

However, they did not prevent a compromised developer endpoint from yielding a valid GitHub token. Following the incident, CrowdSec has deployed endpoint detection and response protection on workstations used to access code or infrastructure.

The company also plans to strengthen GitHub activity monitoring, accelerate credential-review processes, and reinforce employee offboarding procedures.

Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team 

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories