Select a theme from the list.
Insights

From our experts

Latest
CaptiveCrunch Turns Hotel Networks Into Identity and Malware Delivery ChannelsDeparted Employee Access Magnifies the Fallout From the TanStack Supply Chain AttackBragJack Turns Malicious Browser Extensions Into AI Agent ControllersWindows 11 Tests Remote Cloud Rebuild for Faster Enterprise RecoveryPublic Linux Root Exploits Put Unpatched Servers on a Short ClockGyazo Breach Turns Screenshot Metadata Into a Privacy CrisisMicrosoft's Email Benchmark Shows Why Inbox Defense Cannot Stop at DeliveryMalicious DNS Zones Can Turn Unbound Resolvers Into Code-Execution TargetsRatHat Gives Android Malware an AI-Powered Pair of HandsMITRE ATT&CK Splits Hiding From Blinding in Major Defensive Model ChangeParaShells Flaw Leaves Intel Mac Users Without a Confirmed Parallels FixWindows 11 Security Update Knocks Some Enterprise PCs Off Their DomainsCaptiveCrunch Turns Hotel Networks Into Identity and Malware Delivery ChannelsDeparted Employee Access Magnifies the Fallout From the TanStack Supply Chain AttackBragJack Turns Malicious Browser Extensions Into AI Agent ControllersWindows 11 Tests Remote Cloud Rebuild for Faster Enterprise RecoveryPublic Linux Root Exploits Put Unpatched Servers on a Short ClockGyazo Breach Turns Screenshot Metadata Into a Privacy CrisisMicrosoft's Email Benchmark Shows Why Inbox Defense Cannot Stop at DeliveryMalicious DNS Zones Can Turn Unbound Resolvers Into Code-Execution TargetsRatHat Gives Android Malware an AI-Powered Pair of HandsMITRE ATT&CK Splits Hiding From Blinding in Major Defensive Model ChangeParaShells Flaw Leaves Intel Mac Users Without a Confirmed Parallels FixWindows 11 Security Update Knocks Some Enterprise PCs Off Their Domains
Security Insight

Departed Employee Access Magnifies the Fallout From the TanStack Supply Chain Attack

Departed Employee Access Magnifies the Fallout From the TanStack Supply Chain Attack
Photo by panumas nikhomkhai on Pexels

CrowdSec says an attacker copied approximately 170 private GitHub repositories using an OAuth token associated with a recently departed employee. The credential was reportedly stolen during the earlier compromise of malicious TanStack npm packages, illustrating how supply chain malware and incomplete offboarding can combine into a much larger incident. ([thehackernews.com](https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html))

A software supply chain compromise has produced a significant secondary breach at CrowdSec, where an attacker obtained approximately 170 private GitHub repositories. The intrusion did not begin with a direct attack against CrowdSec's servers. Instead, it reportedly relied on a GitHub OAuth token stolen from the laptop of a recently departed employee whose repository access had temporarily remained active.

The laptop was linked to the May 2026 TanStack npm compromise, during which malicious package versions collected developer credentials, including GitHub tokens, SSH keys and cloud credentials. CrowdSec said its repositories were copied on May 22, while the former employee's account was removed from the GitHub organization three days later. The stolen material later appeared on an online forum. ([thehackernews.com](https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html))

More Than a Source Code Leak

The archive reportedly included private web console code, automation scripts, data science material and details about the consensus process used to decide which malicious IP addresses enter CrowdSec blocklists. It also contained email addresses belonging to 83 users and information about 51 potential investors from 2020.

CrowdSec said its operational infrastructure and databases were not accessed and that no source code was modified. Most credentials found in the archive were already invalid, restricted or subsequently rotated. Nevertheless, exposure of internal logic can provide attackers with useful intelligence for evasion, vulnerability research and targeted social engineering.

Lessons for Development Teams

  • Remove repository and cloud access immediately when employment ends.
  • Avoid extending access through personal or unmanaged development devices.
  • Use short-lived tokens and require regular reauthorization.
  • Monitor unusual repository cloning and high-volume API activity.
  • Scan developer endpoints after any ecosystem-wide package compromise.

I believe the most important lesson is that offboarding and supply chain security cannot operate as separate processes. A token stolen today may remain valuable long after the original malware campaign is discovered. Development organizations should assume that credentials exposed during package compromises will be tested against every connected repository, cloud account and automation service. Rapid token revocation is often more important than simply removing the malicious dependency.

Talk to our team →

Latest

CaptiveCrunch Turns Hotel Networks Into Identity and Malware Delivery ChannelsSep 20, 2026Departed Employee Access Magnifies the Fallout From the TanStack Supply Chain AttackSep 20, 2026BragJack Turns Malicious Browser Extensions Into AI Agent ControllersSep 20, 2026Windows 11 Tests Remote Cloud Rebuild for Faster Enterprise RecoverySep 19, 2026Public Linux Root Exploits Put Unpatched Servers on a Short ClockSep 19, 2026Gyazo Breach Turns Screenshot Metadata Into a Privacy CrisisSep 19, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path