Monday, September 21, 2026 · Cyber news, in panels.
CrowdSec says a malicious TanStack dependency likely exposed an API key used to read about 300 repositories, including roughly 170 private ones. Rotate build and repository tokens, audit dependency provenance, and review CI access logs.

CrowdSec Source Code Theft Tied to TanStack Attack

CrowdSec says a malicious TanStack dependency likely exposed an API key used to read about 300 repositories, including roughly 170 private ones. Rotate build and repository tokens, audit dependency provenance, and review CI access logs.

Get tomorrow's comic in your inbox

One panel a day. No spam, unsubscribe with one click.