TeamPCP exploits TanStack supply chain to steal CrowdSec code
TeamPCP exploited a supply chain vulnerability in TanStack packages to compromise 300 repositories, including those belonging to CrowdSec. The attack involved the insertion of 84 malicious artifacts across 42 TanStack packages, leading to the exfiltration of source code. No customer data was leaked, but the breach highlights the risks of third-party dependencies. The attack was confirmed by CrowdSec and corroborated by multiple sources.
- First seen
- 2026-05-01
- Last seen
- 2026-09-21
- Threat actors
- TeamPCP
- Malware
- —
- Sectors
- Technology
- Countries
- France
How it works
TeamPCP exploited a supply chain vulnerability by inserting malicious artifacts into TanStack packages. These malicious packages were then used by CrowdSec, allowing attackers to compromise an API key and access internal repositories. The attackers exfiltrated source code from 300 repositories, including CrowdSec's SaaS console and AWS Cloud routines. No customer data was leaked, but the breach was limited to CrowdSec's internal systems.
Techniques (MITRE ATT&CK)
- T1195 · initial_accessSupply Chain CompromiseTeamPCP published 84 malicious artifacts across 42 TanStack packages, leading to the supply chain compromise.
- T1059 · executionCommand and Scripting InterpreterAttackers likely used a command and scripting interpreter to execute malicious code after compromising an API key.
- T1003 · credential_accessOS Credential DumpingAttackers may have used OS credential dumping techniques to extract credentials after gaining access to internal systems.
- T1040 · credential_accessNetwork SniffingNetwork sniffing was likely used to monitor and exfiltrate sensitive data from internal systems.
Indicators
Indicators associated with this campaign in the sources we reviewed. Corroborate before blocking: an address or domain can be shared infrastructure.
- lapsus.ar.io
What to do
- Review and monitor third-party dependencies for potential vulnerabilities, especially those used in critical systems.
- Implement continuous monitoring and threat detection for supply chain attacks, including third-party package integrity checks.
- Conduct regular security audits and penetration testing of third-party components used in internal systems.
- Ensure that all API keys and credentials are rotated regularly and stored securely to prevent unauthorized access.
- Implement strict access controls and monitoring for internal repositories and codebases to detect unauthorized activity.