Kryptovalutaticker:
sysadmin från Cyber Security News

TanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories

Guru Baran
23 hours ago
5 Visningar
0 Kommentarer
TanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories

CrowdSec has disclosed that attackers copied about 170 private GitHub repositories after a former employee’s account was compromised through May’s TanStack npm supply chain attack. The May 22 theft remained undetected until stolen source code appeared on a cybercrime forum on September 16, showing how a poisoned dependency can outlive its infection window and undermine developer identities. Data Leak Claim The incident traces to CVE-2026-45321, the compromise of TanStack’s Router and Start ecosystem. On May 11, the threat actor chained an unsafe pull_request_target workflow, GitHub Actions cache poisoning, and runtime extraction of an OpenID Connect token to publish 84 malicious releases across 42 @tanstack...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!