CrowdSec GitHub Data Breach: TanStack Supply Chain Attack and Offboarding Failure Analysis

CrowdSec GitHub Data Breach: TanStack Supply Chain Attack and Offboarding Failure Analysis

Executive Summary

On September 18, 2026, CrowdSec disclosed a significant data breach resulting from a sophisticated supply chain attack involving the TanStack npm package repository. The incident originated when the threat actor TeamPCP (UNC6780) compromised TanStack’s GitHub Actions pipeline, enabling the distribution of malicious npm packages containing the “Mini Shai-Hulud” credential-harvesting malware. A CrowdSec employee’s workstation was infected after installing one of these compromised packages, leading to the exfiltration of a GitHub OAuth token. This token was subsequently used by the attacker to clone approximately 170 private CrowdSec GitHub repositories, exposing internal source code, data science models, deployment tooling, and limited personal data. The breach was exacerbated by an incomplete offboarding process, as the compromised credential remained active for several days after the employee’s departure. No client or partner data was included in the leak, and all exposed credentials have since been rotated. The incident highlights the critical risks posed by supply chain attacks and the importance of robust credential management and offboarding procedures (CrowdSec, 2026-09-18; Cloud Security Alliance, 2026-09-20).

Technical Information

The attack on CrowdSec was the result of a multi-stage supply chain compromise, leveraging both technical vulnerabilities in the open-source ecosystem and organizational process failures.

The initial compromise occurred on May 11, 2026, when TeamPCP exploited a misconfiguration in the TanStack project’s GitHub Actions pipeline. By chaining a pull_request_target misconfiguration, workflow cache poisoning, and OIDC token extraction from runner memory, the attacker gained access to publishing credentials. This allowed the attacker to push 84 malicious releases across 42 npm packages, each cryptographically signed to evade detection (Cloud Security Alliance, 2026-09-20; CrowdSec, 2026-09-18).

The malicious packages delivered the “Mini Shai-Hulud” worm, which executed post-install scripts on infected machines. The malware searched for and harvested credentials, including GitHub tokens, npm tokens, SSH keys, and cloud/Kubernetes credentials. If additional npm tokens were found, the malware would automatically publish malicious versions of any accessible npm packages, enabling worm-like propagation across the npm ecosystem (Wiz, 2025-09-16).

A CrowdSec employee’s workstation was infected after installing one of the compromised packages. The malware exfiltrated a GitHub OAuth token, which was then used by the attacker on May 22, 2026, to clone approximately 170 private CrowdSec repositories. The credential remained active due to an incomplete offboarding process, as the employee had departed but was allowed to retain access to finalize work. The token was not revoked until three days after the unauthorized cloning had already occurred (CrowdSec, 2026-09-18; Cloud Security Alliance, 2026-09-20).

The breach exposed internal source code, data science models, deployment tooling, and limited personal data, including 83 email addresses used by the Data Science team and the names and email addresses of 51 potential investors from 2020. No client or partner data was included in the leak. The only credential of potential value was an AWS SNS token, which was properly scoped and has since been rotated. All other exposed credentials were either already rotated or not usable from the internet.

The attack demonstrates the risks associated with supply chain compromises, credential harvesting malware, and incomplete offboarding procedures. The technical sophistication of the “Mini Shai-Hulud” worm, combined with the attacker’s ability to exploit organizational process gaps, resulted in a breach that could have been prevented with stricter credential management and offboarding controls.

Affected Versions & Timeline

The attack chain began with the compromise of the TanStack npm packages on May 11, 2026. The malicious packages were distributed across 42 npm packages, affecting any downstream projects or organizations that installed them. The CrowdSec breach occurred on May 22, 2026, when the attacker used a stolen GitHub OAuth token to clone private repositories. The credential was not revoked until May 25, 2026. The incident was publicly disclosed by CrowdSec on September 18, 2026, following internal investigation and remediation efforts (CrowdSec, 2026-09-18; Cloud Security Alliance, 2026-09-20).

Threat Activity

The threat actor TeamPCP (UNC6780) is attributed with high confidence to this campaign, based on direct claims, technical overlap, and consistent reporting across multiple sources. TeamPCP has a history of targeting open-source supply chains, including the TanStack npm ecosystem, Mistral AI, Trivy, LiteLLM, and Red Hat’s @redhat-cloud-services namespace via the “Miasma” worm. The attacker used BreachForum for data dissemination, with activity traced to a Toronto IP address and the email address diencracked[@]cock[.]li (CrowdSec, 2026-09-18).

The “Mini Shai-Hulud” malware is notable for its credential harvesting and worm-like propagation capabilities. It searches for sensitive tokens and credentials on infected machines and attempts to exfiltrate them to attacker-controlled infrastructure. If additional npm tokens are found, it can automatically publish malicious versions of accessible packages, enabling rapid spread across the npm ecosystem (Wiz, 2025-09-16).

Mitigation & Workarounds

Critical mitigation steps include immediate rotation of all credentials and tokens exposed in the breach, with particular attention to cloud service tokens and GitHub OAuth tokens. Organizations should review and harden offboarding procedures to ensure that all access is revoked promptly when employees depart or change roles. Regular audits of credential usage and access logs are essential to detect unauthorized activity.

High-priority recommendations include implementing automated detection of malicious npm packages, enforcing least-privilege access for all tokens and credentials, and monitoring for anomalous repository cloning or credential usage. Medium-priority actions involve reviewing dependency chains for exposure to compromised packages and enhancing employee security awareness regarding supply chain risks. Low-priority steps include periodic review of open-source contributions and public disclosures for potential exposure.

Indicators of Compromise

The following indicators are provided as a point-in-time reference and should be validated before enforcement in production environments.

Type

Indicator

Reported (date)

Source

 

Email

diencracked[@]cock[.]li

2026-09-18

https://www.crowdsec.net/blog/tanstack-supply-chain-attack-analysis

Domain

cock[.]li

2026-09-18

https://www.crowdsec.net/blog/tanstack-supply-chain-attack-analysis

References

CrowdSec Official Disclosure: "TanStack Supply Chain Attack Analysis", September 18, 2026, https://www.crowdsec.net/blog/tanstack-supply-chain-attack-analysis

Cloud Security Alliance Research Note: "CrowdSec Breach: TanStack Fallout Meets Offboarding Failure", September 20, 2026, https://labs.cloudsecurityalliance.org/research/csa-research-note-crowdsec-tanstack-offboarding-breach-20260/

Wiz Technical Analysis: "Shai-Hulud npm Supply Chain Attack", September 16, 2025, https://www.wiz.io/blog/shai-hulud-npm-supply-chain-attack

About Rescana

Rescana provides a Third-Party Risk Management (TPRM) platform that enables organizations to continuously monitor and assess the security posture of their vendors and supply chain partners. Our platform supports automated detection of supply chain risks, credential exposures, and offboarding gaps, helping organizations reduce the likelihood and impact of incidents similar to the one described in this report.

We are happy to answer questions at info@rescana.com.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.