Security & supply chainThe CrowdSec leak is a lesson in the OAuth token you forgot to revoke
About 170 private CrowdSec repositories were cloned after the TanStack npm compromise scraped an OAuth token still bound to a former employee's account, per a DevOps.com report. The pivot vector was an OAuth-app grant nobody had audited.