← Blog

CrowdSec Leak: 170 Private Repos After TanStack Stealer

Share on X

CrowdSec confirmed that about 170 private GitHub repositories were copied on May 22, 2026, using a GitHub OAuth token from an employee who had just left — after that laptop was hit by the TanStack npm credential-stealer wave (CVE-2026-45321). The archive appeared on a forum September 16. The September 18 write-up lists 83 user emails and 51 potential investors’ names, emails, and investment context.

Verified via CrowdSec blogs. Canonical: https://breachhistory.com/crowdsec/crowdsec-github-tanstack2026.

How it worked

Malicious TanStack packages stole developer credentials in May. Offboarding left GitHub org access open briefly. On May 22 an attacker cloned private repos; the account left May 25. Infrastructure and databases were not accessed; code was not modified. An AWS SNS credential was probed August 17 without further success.

What leaked

Private SaaS console, data-science, automation, and consensus-algorithm code — including previously unpublished blocklist thresholds — plus limited user and investor contact data.

What you should do

  1. Users among the 83: watch phishing using your product email.
  2. Investors: verify CrowdSec outreach out-of-band.
  3. Revoke leaver GitHub access the same day.
  4. Audit lockfiles for TanStack CVE-2026-45321 windows.
  5. Rotate GitHub tokens that lived on May laptops.
  6. Require endpoint protection on machines with org OAuth tokens.
  7. Assume consensus thresholds are public now.
  8. No password reset solely from this notice unless CrowdSec contacts you.
  9. Open-source contributors: do not paste the private archive into forks.
  10. Security teams: tabletop npm stealer → GitHub clone this quarter.

Industry context

Readers comparing this incident to other September 2026 disclosures should separate company-attested facts from actor marketing. Leak-site volume claims, raw row counts, and “complete archive” language are negotiation tools. Regulators and Have I Been Pwned-style analyses often cut those numbers dramatically once duplicates are removed.

Phishing follows every headline. Attackers will reuse the real organization name, a plausible deadline, and a payment or “secure portal” theme. Help desks should verify using phone numbers from letterhead, not from the inbound message.

If forensics later revise scope, publish an amendment with dates. Catalogs should track those amendments so researchers are not citing stale counts.

Canonical record and sources

CrowdSec catalog entry

Evidence-folder note 1 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 2 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 3 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 4 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 5 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 6 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 7 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 8 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 9 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 10 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 11 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 12 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 13 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 14 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 15 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 16 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 17 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 18 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 19 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 20 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 21 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 22 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 23 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 24 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 25 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 26 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 27 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 28 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 29 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 30 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 31 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 32 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 33 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 34 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 35 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 36 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 37 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 38 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 39 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 40 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 41 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 42 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 43 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 44 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 45 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 46 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 47 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 48 for crowdsec-github-tanstack-leak-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.