The Hacker NewsSunday · September 20, 2026FREE

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

securitynpmgithubsupply-chain

CrowdSec says an attack on the TanStack npm package led to a copy of 170 private GitHub repositories, according to a report published by The Hacker News on September 19, 2026. The headline ties two elements together: an attack on the TanStack npm package and the copying of 170 private GitHub repositories. CrowdSec is the source of that finding as presented in the report. The provided source text contains only the headline and page markup, so no additional details are available about how the repositories were accessed, which repositories were involved, or who was affected. The report does not describe the mechanism of the npm attack, the timeline of events, or any response from TanStack, GitHub, or CrowdSec beyond the attribution of the finding. Because the excerpt is limited to the title, the digest is restricted to what that title states: CrowdSec links the TanStack npm attack to the copying of 170 private GitHub repositories.

// why it matters

The report links an npm package attack to the copying of 170 private GitHub repositories, a supply-chain risk for developers relying on npm packages.

Sources

Primary · The Hacker News
▸ Read original at thehackernews.com

Like this? Get the next digest.

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories — aigest.dev