Vulnerabilities & PatchesEmerging1 src
TanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories
CrowdSec has disclosed that attackers copied about 170 private GitHub repositories after a former employee’s account was compromised through May’s TanStack npm supply chain attack.
The May 22 theft remained undetected until stolen source code appeared on a cybercrime forum on September 16, showing how a poisoned dependency can outlive its infection window and undermine developer identities.
Data Leak Claim
The incident traces to CVE-2026-45321 , the compromise of TanStack’s Router and Start ecosystem. On May 11, the threat actor chained an unsafe pull_request_target workflow, GitHub Actions cache poisoning, and runtime extraction of an OpenID Connect token to publish 84 malicious releases across 42 @tanstack packages.