OffPerimeter · Threat advisories
Campaign advisory
lowPublished 2026-09-29 · 1 indicators

TeamPCP exploits TanStack supply chain to steal CrowdSec code

TeamPCP exploited a supply chain vulnerability in TanStack packages to compromise 300 repositories, including those belonging to CrowdSec. The attack involved the insertion of 84 malicious artifacts across 42 TanStack packages, leading to the exfiltration of source code. No customer data was leaked, but the breach highlights the risks of third-party dependencies. The attack was confirmed by CrowdSec and corroborated by multiple sources.

ShareXLinkedInWhatsApp
First seen
2026-05-01
Last seen
2026-09-21
Threat actors
TeamPCP
Malware
—
Sectors
Technology
Countries
France

How it works

TeamPCP exploited a supply chain vulnerability by inserting malicious artifacts into TanStack packages. These malicious packages were then used by CrowdSec, allowing attackers to compromise an API key and access internal repositories. The attackers exfiltrated source code from 300 repositories, including CrowdSec's SaaS console and AWS Cloud routines. No customer data was leaked, but the breach was limited to CrowdSec's internal systems.

Techniques (MITRE ATT&CK)

Indicators

Indicators associated with this campaign in the sources we reviewed. Corroborate before blocking: an address or domain can be shared infrastructure.

Domains (1)
  • lapsus.ar.io

What to do

References

ShareXLinkedInWhatsApp