SECURITY·중요도 7·2026. 09. 19.·The Hacker News
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
── KO ──────────────────
CrowdSec의 170개의 프라이빗 GitHub 저장소가 공격당했다.
CrowdSec는 퇴사한 직원의 계정을 통해 약 170개의 프라이빗 GitHub 저장소가 복사당했다고 발표했다. 이 사건은 5월 22일 발생했으며, 공격자는 TanStack의 npm 패키지에서 발생한 공급망 공격으로 인해 자격 증명을 훔쳤다. CrowdSec는 해당 직원의 GitHub 접근 권한이 계속 열려 있었다고 밝혔다.
── EN ──────────────────
CrowdSec's 170 private GitHub repositories were compromised.
CrowdSec reported that around 170 private GitHub repositories were copied using the account of a recently departed employee. This incident occurred on May 22, and the attacker exploited a supply chain attack on TanStack's npm packages to steal credentials. CrowdSec noted that the employee's GitHub access remained open.