CrowdSec Source Code Stolen in TanStack Supply Chain Attack
Want more insights like this?
French cybersecurity firm CrowdSec confirmed that attackers copied roughly 170 of its private GitHub repositories in May 2026, a theft that only came to light when the archive appeared on a hacking forum on September 16.
CrowdSec traced the breach to the May 11 TanStack supply chain attack, in which an attacker published 84 malicious versions across 42 npm packages. The malware compromised a recently departed developer still in CrowdSec's GitHub organization, whose OAuth token was used to clone the code on May 22.
The private code covers CrowdSec's SaaS console, AWS cloud routines, connectors, and automations. The dump also held the email addresses of 83 users and the names, emails, and investment context of 51 prospective investors from 2020, which CrowdSec is reporting to them and the authorities.
CrowdSec has rotated all exposed credentials. It says the code has little value outside its own environment, though it concedes full source access could speed up hunting for weaknesses.
Source: CrowdSec