CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories (thehackernews.com)
from tonytins@pawb.social to cybersecurity@infosec.pub on 19 Sep 15:54
https://pawb.social/post/50287756

An attacker copied about 170 of CrowdSec’s private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.

The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May’s supply chain attack on TanStack, in which malicious versions of TanStack’s npm packages stole credentials from developers’ machines.

The code appeared on an online forum on September 16. Along with the source code, it contained the email addresses of 83 CrowdSec users and the names, email addresses, and investment context of 51 potential investors from 2020, the company said.

CrowdSec says the account was used only to copy code, that its infrastructure and databases were not accessed, and that no code was changed.

#cybersecurity

threaded - newest