{
  "id": 8412423,
  "title": "CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories",
  "url": "https://urgent.news/2026/09/19/crowdsec-says-tanstack-npm-attack-led-to-copy-of-170-private-github",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-19T07:14:54.000Z",
  "source": {
    "name": "The Hacker News",
    "slug": "the-hacker-news",
    "url": "https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html"
  },
  "original_language": "en",
  "account": null,
  "summary": "An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}