← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 21, 2026 · 05:20via CyberPress

TanStack NPM Supply Chain Attack Exposes 170 Private CrowdSec GitHub Repositories

Brief

CrowdSec has disclosed that a May 2026 compromise tied to the TanStack npm supply-chain incident enabled attackers to clone roughly 170 private GitHub repositories, exposing internal source code and limited sensitive contact data.

The company said the intrusion was traced to a former employee’s GitHub OAuth token, which attackers allegedly obtained through the broader TanStack compromise attributed to TeamPCP, also tracked as UNC6780.

CrowdSec emphasized that its production infrastructure, databases, CI/CD pipelines , and open-source code were not altered or directly compromised.

TanStack NPM Supply Chain Attack

TeamPCP compromised the TanStack npm ecosystem on May 11, backdooring 42 packages with the credential-harvesting malware known as Shai Hulud.

The malicious campaign targeted developer environments for GitHub tokens, cloud credentials, SSH keys, and other secrets.

Read more on CyberPress