TanStack NPM Supply Chain Attack Exposes 170 Private CrowdSec GitHub Repositories
Brief
CrowdSec has disclosed that a May 2026 compromise tied to the TanStack npm supply-chain incident enabled attackers to clone roughly 170 private GitHub repositories, exposing internal source code and limited sensitive contact data.
The company said the intrusion was traced to a former employee’s GitHub OAuth token, which attackers allegedly obtained through the broader TanStack compromise attributed to TeamPCP, also tracked as UNC6780.
CrowdSec emphasized that its production infrastructure, databases, CI/CD pipelines , and open-source code were not altered or directly compromised.
TanStack NPM Supply Chain Attack
TeamPCP compromised the TanStack npm ecosystem on May 11, backdooring 42 packages with the credential-harvesting malware known as Shai Hulud.
The malicious campaign targeted developer environments for GitHub tokens, cloud credentials, SSH keys, and other secrets.
