CrowdSec loses 170 private repos to the TanStack npm chain and a botched offboarding
On September 18, 2026, CrowdSec revealed that an attacker copied about 170 private GitHub repositories in May using the account of a former employee whose access had never been revoked. The initial compromise came from TanStack’s malicious npm packages, which also hit Mistral AI and OpenAI.