Kryptovaluta-ticker:
sysadmin fra Cyber Security News

TanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories

Guru Baran
23 hours ago
3 Visninger
0 Kommentarer
TanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories

CrowdSec has disclosed that attackers copied about 170 private GitHub repositories after a former employee’s account was compromised through May’s TanStack npm supply chain attack. The May 22 theft remained undetected until stolen source code appeared on a cybercrime forum on September 16, showing how a poisoned dependency can outlive its infection window and undermine developer identities. Data Leak Claim The incident traces to CVE-2026-45321, the compromise of TanStack’s Router and Start ecosystem. On May 11, the threat actor chained an unsafe pull_request_target workflow, GitHub Actions cache poisoning, and runtime extraction of an OpenID Connect token to publish 84 malicious releases across 42 @tanstack...

Les hele artikkelen hos kilden.

Delta i diskusjonen — kommenter, stem og del lenker.

Registrer
Var dette nyttig?
Del:

Kommentarer (0)

Vennligst logg inn eller registrer deg for å delta i diskusjonen

Ingen kommentarer ennå. Bli den første til å kommentere!