CrowdSec Reports Private GitHub Repository Exposure Following TanStack Supply Chain Attack
Former employee's unrevoked GitHub access allowed attacker to copy 170 repositories in May 2026

Key Takeaways
- Approximately 170 private CrowdSec GitHub repositories were copied by an attacker on May 22, 2026.
- The breach was facilitated by a former employee's GitHub access remaining active after departure.
- The initial compromise is linked to the May 2026 supply chain attack on TanStack npm packages.
Related Security News

Bitget Reports $388M Loss Following Exploitation of Third-Party Security Product Flaw
Bitget disclosed that an attacker stole approximately $388 million by exploiting a vulnerability in a third-party security product integrated into the exchange's infrastructure. The threat actor used the flaw to obtain high-level internal credentials, which were subsequently used on September 24 to issue fraudulent withdrawal commands to Bitget's wallet system. The exchange confirmed that most user funds remain secure, though the full extent of exposure is under investigation.




