# CrowdSec says TanStack attack exposed private code repositories

_Published Saturday, September 19, 2026 at 8:06 AM EDT · Security · Latest · Tier 2 — Notable_

![CrowdSec says TanStack attack exposed private code repositories — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1oastBaXn1Z-Cqbx-BPWZb2oSsgDseV8bReFs787OUvmfsQxJppvU6Fq_uUY_yrCdz1Z4xuevbNRdG88X9lnejn0NUF2RILOB8VxTm8lGXQ6VpZ1hPPqfmC4U86Ci2iYpIqpjy_3H3rCxJe6_9AKm0U9vgO6GHGrDHaKSdzCcFfgpUolbZvSB6VPbCC8/s1700-nu-rw-lo-l85-e365/crowdsec.jpg)

CrowdSec said September 18 that an attacker copied about 170 private GitHub repositories using the account of a recently departed employee whose laptop was compromised in May's TanStack npm supply-chain attack. The company said the copied archive later appeared online and included 83 user email addresses plus information on 51 potential investors. CrowdSec said its infrastructure and databases were not accessed and no code was changed. It said exposed credentials were rotated on September 16 and 17.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html)

---
Canonical: https://techandbusiness.org/newswire/puZufxaGBtu10hyjuEMPay
Published: 2026-09-19T12:06:18.230Z
Story chronology: 2026-09-18T00:00:00.000Z
Retrieved: 2026-09-19T14:25:36.716Z
Publisher: Tech & Business (techandbusiness.org)
