<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

TanStack Attack Exposed 170 Private CrowdSec Repositories

Attackers used a token stolen from a former CrowdSec developer to copy the company's private source code, and nobody noticed for nearly four months.
Content Team

Malicious releases across 42 @tanstack npm packages, published May 11, harvested GitHub tokens, SSH keys, and cloud credentials from developer machines. One belonged to a CrowdSec developer who had just left, whose access the company kept open so he could finish outstanding work. On May 22 an attacker used his OAuth token to clone roughly 170 private repositories from a Toronto IP address in nine minutes.

CrowdSec revoked the account on May 25, three days after the clone, and learned of the theft only on September 16, when the code appeared on a breach forum. The archive held the SaaS console, data-science models, deployment tools, email addresses for 83 users — under 0.05% of its user base — and names and investment details for 51 potential investors from 2020.

Production systems, databases, and the CrowdSec agent and blocklist data were untouched, and no code was altered. The one live credential was an AWS token scoped to a single SNS topic, probed on August 17 and taken no further. CrowdSec's own lesson is blunt: multi-factor authentication cannot stop malware that already holds a valid token, and only enterprise GitHub plans retain git activity, on a rolling seven-day window.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo