CrowdSec and TanStack: Hackers Exploit TanStack Supply Chain Attack to Steal 170 Private CrowdSec Repositories

CrowdSec and TanStack: Hackers Exploit TanStack Supply Chain Attack to Steal 170 Private CrowdSec Repositories

CrowdSec Repositories Compromised via Stolen GitHub OAuth Token in Supply Chain Attack

In a supply chain attack linked to the TanStack npm compromise, threat actors TeamPCP (UNC6780) exploited a stolen GitHub OAuth token to clone 170 private CrowdSec repositories, exposing source code, limited user contact details, and a restricted AWS credential.

The breach originated from a former employee’s GitHub account, which remained active for transition purposes. The account was compromised in May, with unauthorized access occurring between 05:52 and 06:01 UTC on May 22. CrowdSec removed the account three days later but did not disclose the incident publicly until September 16.

The attackers, who backdoored 42 npm packages with the Shai Hulud malware on May 11, used the stolen OAuth token to download repositories from an IP address in Toronto, Canada. The cloned data included 130+ public and private repositories, containing CrowdSec’s SaaS console code, automation tools, and Consensus Algorithm though no sensitive customer data or production infrastructure was accessed.

While the exposed code could help adversaries identify vulnerabilities, CrowdSec stated that its Consensus Algorithm which determines IP blocklist additions relies on distributed security engines, making manipulation difficult. The company also confirmed that no malicious commits or infrastructure changes occurred.

A still-valid AWS SNS credential in the leaked archive was tested on August 17 from an unidentified IP, but its restricted permissions prevented further exploitation. The breach also exposed email addresses of 83 users (less than 0.05% of CrowdSec’s user base) and investor details from 2020, prompting notifications to affected individuals.

CrowdSec responded by rotating credentials, revoking tokens, and conducting forensic reviews, with assistance from GitHub, GitGuardian, Aikido, and Fuites Info. The incident highlights risks in developer credential exposure and the need for stricter offboarding controls and faster incident response.

Source: https://gbhackers.com/hackers-exploit-tanstack-supply-chain-attack/

CrowdSec cybersecurity rating report: https://www.rankiteo.com/company/crowdsec

TanStack cybersecurity rating report: https://www.rankiteo.com/company/tanstack

"id": "CROTAN1789971988",
"linkid": "crowdsec, tanstack",
"type": "Breach",
"date": "5/2026",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': '83 users (less than 0.05% of '
                                              'user base)',
                        'industry': 'Cybersecurity',
                        'name': 'CrowdSec',
                        'type': 'Company'}],
 'attack_vector': 'Stolen GitHub OAuth Token',
 'customer_advisories': 'Notifications sent to affected individuals',
 'data_breach': {'data_exfiltration': 'Yes (cloned repositories)',
                 'number_of_records_exposed': '170 repositories, 83 user email '
                                              'addresses',
                 'personally_identifiable_information': 'Email addresses of 83 '
                                                        'users, investor '
                                                        'details from 2020',
                 'sensitivity_of_data': 'Moderate (no sensitive customer data '
                                        'or production infrastructure)',
                 'type_of_data_compromised': ['Source code',
                                              'Email addresses',
                                              'Investor details',
                                              'AWS SNS credential']},
 'date_detected': '2024-05-22T05:52:00Z',
 'date_publicly_disclosed': '2024-09-16',
 'description': 'In a supply chain attack linked to the TanStack npm '
                'compromise, threat actors TeamPCP (UNC6780) exploited a '
                'stolen GitHub OAuth token to clone 170 private CrowdSec '
                'repositories, exposing source code, limited user contact '
                'details, and a restricted AWS credential. The breach '
                'originated from a former employee’s GitHub account, which was '
                'compromised in May and used for unauthorized access between '
                '05:52 and 06:01 UTC on May 22. CrowdSec removed the account '
                'three days later but did not disclose the incident publicly '
                'until September 16.',
 'impact': {'brand_reputation_impact': 'Yes',
            'data_compromised': 'Source code, limited user contact details, '
                                'restricted AWS credential',
            'identity_theft_risk': 'Limited (email addresses of 83 users '
                                   'exposed)',
            'operational_impact': 'Potential vulnerability identification by '
                                  'adversaries',
            'systems_affected': '170 private repositories, SaaS console code, '
                                'automation tools, Consensus Algorithm'},
 'initial_access_broker': {'entry_point': 'Stolen GitHub OAuth token from '
                                          'former employee account',
                           'high_value_targets': 'Private repositories, SaaS '
                                                 'console code, Consensus '
                                                 'Algorithm'},
 'investigation_status': 'Completed (forensic review)',
 'lessons_learned': 'Risks in developer credential exposure, need for stricter '
                    'offboarding controls and faster incident response',
 'post_incident_analysis': {'corrective_actions': 'Credential rotation, token '
                                                  'revocation, stricter '
                                                  'offboarding controls, '
                                                  'faster incident response',
                            'root_causes': 'Compromised former employee GitHub '
                                           'account, delayed account removal, '
                                           'exposed OAuth token'},
 'references': [{'source': 'CrowdSec Public Disclosure'}],
 'response': {'communication_strategy': 'Public disclosure on September 16',
              'containment_measures': 'Account removal, credential rotation, '
                                      'token revocation',
              'incident_response_plan_activated': 'Yes',
              'remediation_measures': 'Forensic reviews, notifications to '
                                      'affected individuals',
              'third_party_assistance': 'GitHub, GitGuardian, Aikido, Fuites '
                                        'Info'},
 'threat_actor': 'TeamPCP (UNC6780)',
 'title': 'CrowdSec Repositories Compromised via Stolen GitHub OAuth Token in '
          'Supply Chain Attack',
 'type': 'Supply Chain Attack',
 'vulnerability_exploited': 'Compromised former employee GitHub account'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.