MemTensor's Latest Tag Was the Implant. Clean Builds Lasted Minutes.
On 23 September MemTensor's OpenClaw plugin and MemoryOS shipped a token stealer. Clean builds lasted minutes. Pulling the versions did not end the impact clock.
CrowdSec said on 17 September a May TanStack install likely stole a CI token and read private GitHub repos. SaaS and AWS code. No customer data. Notice in September.
CrowdSec confirmed on 17 September that private GitHub repositories were read in May. The likely vector is a poisoned TanStack package that pulled a CI token with read access. Exposed code includes the SaaS console, AWS routines, connectors, and automations. CrowdSec says no customer data left. Fuites Infos reported it on 16 September, four months later.
Hacker News put CrowdSec's own statement on the front page this evening. The company learned on 16 September that private GitHub repositories had been read in May. It confirmed the report today.
US X Trends were football. The security side of X spent the night on Plugin4Shell and a Mistral listing. This is the vendor who said the quiet part: the May TanStack install was not only a package story.
High CI token, private-repo read, four months to notice. High because the access sat until an outsider called, not because CrowdSec says customer data left.
The vendor page, 17 September. Not a diagram.
The Hacker News thread that put it on the front page.
On 16 September, Fuites Infos told CrowdSec about a source-code leak. The company verified it and published on the 17th. The access, it says, happened in May.
Two trees. The Security Engine is public by design and out of scope. The private tree holds the SaaS console, some AWS cloud routines, connectors, and automations. Headlines that say 300 repositories are, in CrowdSec's wording, true only if you add the 130-plus public repos. That number is a split, not a volume claim.
No client data, login material, names, or organizations, per the statement. CrowdSec does not store customer PII or client logs. A hunt for tokens that would let someone move laterally found none so far. The API material in the leak is, they say, the CI/CD token itself.
The likely vector is the TanStack npm compromise of 11 May. CrowdSec says the same class hit Mistral AI. A TanStack component in use that month looks, to them, to have been backdoored to extract an API key that could read the private codebase. The leak was only exploitable in a short May window. They rotated the tokens after confirming the report.
TanStack's postmortem is dated 15 May. CVE-2026-45321 covers 84 malicious versions across 42 packages, published in a six-minute window on the 11th. The payload's job was to steal cloud credentials and GitHub tokens from the install host.
CrowdSec is a later confirmation that one of those tokens was used, and that the company did not see the private-repo read until September. RuntimeWire's write-up puts the gap at roughly four months. Hacker News did the predictable joke. The operator line is less funny: a runner that can install a dependency and also hold a git token with private read is a second product.
It is not a September intrusion. September is the notice. May is the access.
It is not the July Hugging Face swarm, and it is not last night's Mistral listing. CrowdSec cites Mistral as the earlier TanStack cousin. A new forum post selling 339 files is a separate claim. Do not merge them.
It is also not a CrowdStrike headline. Different company. The HN thread already went there.
If you run CrowdSec, or you ran a JS install on 11 May:
Hacker News will keep arguing about IP blocklists. The fileable ticket is a May install that read a security company's private git, and a September phone call that was the first the company heard of it. Scope the token. Then read May as if someone already cloned it.
CrowdSec says no. It does not store customer PII or client logs, and the hunt for login material, names, and organizations in the leaked tree found none. Treat that as the company's statement, not as a third-party audit. The ticket on your side is still the CI token class, not a customer-dump headline.
No. CrowdSec dates the access to a short window in May. September is when Fuites Infos told them and when they published. Headlines that say 300 repositories are, in CrowdSec's words, counting public Security Engine repos plus the private split. Do not file this as a fresh September intrusion.
CrowdSec says the TanStack compromise is the likely vector, as in the Mistral AI case. TanStack's own advisory is GHSA-g7cv-rxg3-hmpx / CVE-2026-45321: 84 malicious versions across 42 packages on 11 May, built to steal cloud credentials and GitHub tokens. CrowdSec is a later confirmation that one of those tokens was used. It is not a new npm publish.
Read the 17 September statement. Rotate any CrowdSec-issued tokens you were told to rotate. Hunt May CI logs for TanStack installs and unexpected GitHub clone traffic from those runners. This is not a reason to rip out the open Security Engine. It is a reason to treat May CI credentials as burned if that runner could reach private git.
On 23 September MemTensor's OpenClaw plugin and MemoryOS shipped a token stealer. Clean builds lasted minutes. Pulling the versions did not end the impact clock.
Hacker News: SafeDep found an npm mathjs clone whose solver unlocks a RAT. JFrog cracked the trigger. The GitHub tree was clean. The tarball was not.
Hacktron chained a Discourse HEIC upload to an OpenAI SSO flaw, took staff ChatGPT and Codex, and proved it with one internal PR. OpenAI paid $6,500.