[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_AVSZttWive4hE2VY8pCdnTSyl2PX5boMfi_nrCAwhQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":44},"96cd57d4-ab08-41f6-b067-cc0989a3e1d7","compromised-npm-package-leads-to-theft-of-170-private-github-repos","e4717926-7802-4bc3-afbb-5717c1f4c47d","Compromised npm Package Leads to Theft of 170 Private GitHub Repos","A malicious supply chain attack targeting TanStack's npm packages allowed an attacker to steal GitHub tokens from a former employee's laptop, granting unauthorized access to approximately 170 of CrowdSec's private repositories. The core failure was twofold: a compromised third-party dependency silently harvested credentials, and offboarding processes failed to revoke the former employee's access tokens before the breach occurred. Stolen data included source code, user information, and investor data — demonstrating that supply chain compromises can cascade far beyond their initial entry point. This incident highlights how a single unrotated credential from a departed employee can expose an entire organization's codebase.","**Immediate actions:**\n- Audit and revoke all GitHub tokens, API keys, and credentials associated with former employees immediately upon offboarding.\n- Review and remove any npm packages flagged as compromised (e.g., affected TanStack versions) from all active development environments.\n- Rotate all organization-wide secrets and tokens as a precautionary measure following any suspected supply chain compromise.\n\n**Long-term improvements:**\n- Implement automated offboarding workflows that instantly revoke all access tokens, OAuth grants, and repository permissions when an employee leaves.\n- Enforce short-lived, auto-expiring tokens (e.g., via GitHub fine-grained PATs) to limit the blast radius of any stolen credential.\n- Establish a software composition analysis (SCA) pipeline to continuously audit third-party npm dependencies for known-malicious or tampered packages.\n\n**Detection measures:**\n- Enable GitHub audit log streaming and alert on anomalous repository cloning activity, especially bulk downloads or access from unexpected geolocations.\n- Implement secrets scanning across all repositories and CI\u002FCD pipelines to detect exposed credentials before they can be exploited.\n- Monitor developer endpoints for credential-harvesting behaviors using endpoint detection and response (EDR) tooling.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 5: Account Management","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management","NIST AC-2: Account Management","NIST AC-3: Access Enforcement","NIST SI-7: Software, Firmware, and Information Integrity","NIST IR-6: Incident Reporting","GDPR Article 32: Security of Processing","GDPR Article 33: Notification of a Personal Data Breach","ITIL: Change and Release Management (dependency vetting)","SLSA Framework: Supply-chain Levels for Software Artifacts","published","2026-09-19T08:20:19.696745+00:00","2026-09-19T08:20:19.366+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fcrowdsec-says-tanstack-npm-attack-led.html","crowdsec-says-tanstack-npm-attack-led-to-copy-of-170-private-github-repositories-47bdb8","CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories",[32,38],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":39,"name":40,"slug":41,"description":42,"color":43},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[45],{"id":46,"date":47,"edition":48,"title":49,"audio_url":50},"74e568f4-38a0-4b8f-a128-3d071d92d7bd","2026-09-19","afternoon","ThreatNoir Weekend Brief — September 19","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-19\u002Fthreatnoir-afternoon-brief-2026-09-19.mp3"]