CrowdSec Source Code Theft Tied to TanStack Attack
CrowdSec says a malicious TanStack dependency likely exposed an API key used to read about 300 repositories, including roughly 170 private ones. Rotate build and repository tokens, audit dependency provenance, and review CI access logs.