CyberHighSingle-sourceBuilding
6.7
Malicious NPM Package 'indexed-btree' Masquerades as 'sorted-btree', Millions of Downloads
SecurityWeekLO·about 9 hours ago
Threat actors exfiltrated 170 private repositories from CrowdSec's GitHub using an OAuth token stolen from a former employee's machine, linked to the TanStack npm supply chain attack. The incident underscores persistent risks from third-party supply chain compromises and credential reuse. Impact on CrowdSec's operations or customers remains unconfirmed.