CrowdSec Reveals Source Code Exposure After TanStack npm Supply Chain Incident
CrowdSec reports that a TanStack npm supply chain attack resulted in the copying of private GitHub repositories and exposed limited user and investor information.
CrowdSec reports that a TanStack npm supply chain attack resulted in the copying of private GitHub repositories and exposed limited user and investor information.
Cybersecurity researchers have uncovered a supply chain attack involving the codexui-android npm package, exposing OpenAI Codex authentication tokens through a malicious exfiltration mechanism affecting developers and Android app users.
On September 8, 2025, attackers republished 18 popular npm packages—including Chalk, Debug and Strip-ANSI—adding malicious code that targeted Web3 wallets. The phishing-driven breach exposed how a single compromised maintainer can turn 2.6 billion weekly downloads into a global supply chain weapon.