<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Github-Breach on CuraSec</title><link>https://curasec.metacog.co.kr/tags/github-breach/</link><description>Recent content in Github-Breach on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 19 Sep 2026 14:22:25 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/github-breach/index.xml" rel="self" type="application/rss+xml"/><item><title>TanStack npm Supply Chain Attack Led to CrowdSec GitHub Repo Exfiltration</title><link>https://curasec.metacog.co.kr/insights/2026-09-19-crowdsec-says-tanstack-npm-attack-led-to-copy-of-170-private/</link><pubDate>Sat, 19 Sep 2026 14:22:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-19-crowdsec-says-tanstack-npm-attack-led-to-copy-of-170-private/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> The TanStack npm supply chain attack in May stole credentials from developer machines; audit your lockfiles for malicious TanStack package versions from that window and rotate any npm tokens or GitHub credentials that may have been exposed. Also verify offboarding checklists immediately revoke GitHub org access upon employee departure.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> This incident had roughly a 4-month dwell time before discovery; build or tune detections for bulk GitHub repository cloning events and unusual API access patterns from recently offboarded accounts — no specific IOCs are published yet to enable an immediate sweep.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> CrowdSec, a security vendor, confirmed ~170 private repositories were exfiltrated; if your organization uses CrowdSec products, request an incident attestation to understand whether any shared intelligence or configurations were exposed. Separately, this breach stemmed from a failed offboarding — review your own access-revocation policy and confirm it mandates same-day removal of all VCS and cloud access.&lt;/li>
&lt;/ul></description></item></channel></rss>