Skip to main content
CyberConfirmedMediumDeveloping
5.6

CrowdSec GitHub Breach via Stolen OAuth Token from TanStack npm Attack

Threat actors exfiltrated 170 private repositories from CrowdSec's GitHub using an OAuth token stolen from a former employee's machine, linked to the TanStack npm supply chain attack. The incident underscores persistent risks from third-party supply chain compromises and credential reuse. Impact on CrowdSec's operations or customers remains unconfirmed.

Dark Readingabout 3 hours agoengCredibility 25%View source

Score Breakdown

Mosaic Score5.6
Confidence0.7
Significance0.5
Source credibility0.3
Source

Related signals

8 found