The TanStack Breach Had a Four-Month Tail: CrowdSec Lost 170 Private Repos
On May 11, 2026, attackers compromised the TanStack npm supply chain — 84 malicious versions across 42 packages. The attack chained GitHub Actions vulnerabilities to steal credentials from thousands of developer environments.
On May 22, 2026 — eleven days later — those stolen credentials were used to exfiltrate 170 private CrowdSec GitHub repositories. CrowdSec's entire private codebase, gone.
They didn't find out until September 16, 2026, when the stolen source code showed up on a cybercrime forum.
Four months. That's the detection gap between the theft and the discovery.
What Actually Happened
The May 11 TanStack attack used a pull_request_target exploit, GitHub Actions cache poisoning, and OIDC token extraction from runner memory. The attackers published malicious packages that looked legitimate because they used real maintainer credentials.
One of those malicious packages landed on a laptop belonging to a former CrowdSec employee. The employee's laptop still had GitHub access. And the attacker's code harvested it.
May 22: The attacker cloned approximately 170 of CrowdSec's private repositories.
September 16: The stolen source code appeared on a cybercrime forum, and CrowdSec learned their entire private codebase had been out in the wild for four months.
The Failures Stack
Former employee device still enrolled. Offboarding didn't revoke GitHub access or remotely wipe the device. The laptop remained a valid authenticated endpoint long after the employee left.
Credential harvesting persisted undetected. The TanStack malicious package ran on the laptop for eleven days post-disclosure before exfiltrating the repos. No endpoint detection caught it.
Bulk repository cloning didn't trigger alerts. 170 private repos cloned in a short window should have lit up monitoring. It didn't. Either there was no monitoring, or the thresholds were set so high that 170 repos in one session looked normal.
Four-month external discovery. CrowdSec didn't detect the theft through their own security controls. They found out when their code showed up for sale.
Supply Chain Attacks Have a Long Tail
The TanStack incident wasn't a one-and-done. It was a credential-harvesting campaign that kept paying dividends months later.
Attackers compromised developer laptops in May. They monetized the access in batches: some credentials used immediately, some held for weeks, some held for months. CrowdSec is one disclosed victim. How many others haven't been disclosed yet?
A recent analysis of 17,022 third-party LLM agent skills found 520 skills with 1,708 credential-security issues, with 89.6% of the leaked credentials immediately exploitable (Chen et al., 2026, https://arxiv.org/abs/2604.03070). That's the new normal: supply chain attacks don't just compromise the target package — they harvest credentials from every developer who installed it, and those credentials unlock thousands of downstream targets.
The Real Risk Is Dormant Access
The TanStack attackers didn't smash and grab. They harvested credentials, then sat on them. Four months later, they were still valid.
That's the threat model enterprises aren't built for. Incident response assumes breaches are detected within hours or days. Compliance frameworks require notification within 72 hours of discovery. But discovery assumes you know you were breached.
If an attacker pulls 170 private repos and doesn't trigger an alert, how long do they have that access before someone notices? The CrowdSec case says: at least four months.
What Should Have Stopped This
Revoke all access on offboarding. The former employee's laptop should have lost GitHub access the day they left. Device enrollment, tokens, SSH keys — all of it revoked, remotely, no exceptions.
Monitor for bulk repository access. One authenticated session cloning 170 private repos is not a normal developer workflow. It's either a backup operation (which should be logged and approved) or a breach. Alert on it.
Expire credentials aggressively. Long-lived GitHub tokens and SSH keys are the problem. If the credentials the TanStack malware harvested had been scoped to 24-hour or 7-day lifetimes, the May 22 theft wouldn't have been possible with May 11 credentials.
Track where your code shows up. CrowdSec didn't detect the theft internally. They found out when their code appeared on a forum. Monitoring dark web marketplaces and code-sharing forums for your own repositories is now table stakes.
The Attribution
The CrowdSec compromise is attributed to TeamPCP, the threat group behind the TanStack campaign (internally called Mini Shai-Hulud). This wasn't opportunistic. It was deliberate, persistent, and methodical.
Attackers spent eleven days post-TanStack-disclosure harvesting credentials from infected developer environments before anyone started cleaning up. Those credentials unlocked access that stayed valid for months.
What This Means for Everyone Else
If you installed a TanStack package between May 11 and whenever your package manager pulled the clean version, your credentials were harvested. If you had GitHub access, AWS keys, API tokens, SSH keys, or database credentials on that machine, they're in an attacker's credential store.
And if the CrowdSec timeline is any guide, those credentials might not be used for months. The breach you're investigating today might have happened in May. The access still works.
Rotate everything. Not just the credentials you think were on affected systems — everything those systems could have accessed. GitHub tokens, cloud keys, database passwords, API secrets. All of it. Yesterday.
Monitor for anomalous access. Bulk data pulls, off-hours logins, access from unusual geolocations, new device enrollments. If you're not alerting on those, you won't know you were breached until your code shows up for sale.
Audit offboarding. Every former employee device that still has access to your repositories is a ticking time bomb. Revoke it now.
The Four-Month Window Is the Point
CrowdSec is a cybersecurity company. They build intrusion detection tools. And they didn't detect an attacker cloning their entire private codebase until four months later, when it showed up on a forum.
If that's the detection gap for a company whose product is detection, what's the gap for everyone else?
Supply chain attacks don't end when the malicious package is removed. They end when every credential harvested during the compromise is rotated. And if you don't know what was harvested, you don't know when it ends.