CrowdSec Confirms Source Code Stolen in Supply Chain Attack
CrowdSec confirmed attackers stole source code from roughly 300 GitHub repositories via the May 2026 TanStack supply chain attack; no customer data affected.
CrowdSec said roughly 300 GitHub repositories, including about 170 private ones holding SaaS console, AWS routine, connector, and automation code, were compromised with source code stolen. The breach likely stemmed from the May 2026 TanStack supply chain attack, in which TeamPCP published 84 malicious artifacts across 42 packages, compromising an API key. No customer credentials or data were leaked, and the company rotated all potentially affected tokens and credentials shortly after the incident.
- About 300 repositories compromised, including roughly 170 private ones with SaaS, AWS, connector code.
- Linked to May 2026 TanStack attack: TeamPCP published 84 malicious artifacts across 42 packages.
- No customer credentials or data leaked; all potentially affected tokens and credentials rotated.
- Company says stolen code cannot be used out of context and has since evolved.
Full article370 words · extracted from securityweek.com · click to collapse
French cybersecurity firm CrowdSec has confirmed that approximately 300 private and public repositories were compromised and source code was stolen from them.
The company provides open source, crowdsourced threat intelligence, including a lightweight security engine to detect and block attacks targeting servers, networks, and applications.
Last week, the French outfit learned that source code had been stolen from its GitHub repositories in May 2026.
CrowdSec has confirmed the report, noting that both private and public code was exfiltrated, and that roughly 300 repositories were affected, including approximately 170 private ones.
“The private part contains the source code for our SaaS console, some AWS Cloud routines, some connectors, and automations,” the company said.
According to CrowdSec, no credentials or other types of data related to its customers were leaked, and the impact is limited to its own organization.
Advertisement. Scroll to continue reading.
“Our team quickly hunted for any token, credential, or sensitive leak that could enable lateral movement but found none so far,” it said.
Additionally, the cybersecurity firm says that, while valuable, the code stolen from its private repositories cannot be used to cause harm, as it can not replicate its network and can only be used with its data and tools; therefore, it cannot be used out of context.
“We regularly audited the SaaS source code, and its leakage shouldn’t pose an immediate threat either. Most of the leaked code has evolved significantly over those four months, but we will closely monitor for any abnormal activity,” CrowdSec says.
The data breach, it explains, was likely a direct result of the May 2026 TanStack supply chain attack, in which TeamPCP published 84 malicious artifacts across 42 TanStack packages.
Because CrowdSec used a TanStack package in May, the malware used in the campaign likely compromised an API key that allowed the attackers to read its private codebase.
The leak likely occurred in May, during the short exploitation window, and CrowdSec immediately rotated all potentially affected tokens and credentials.
Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related: Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Related: Rust Supply Chain Attack Linked to North Korean Hackers
Related: 23 Million User Records Compromised in Gyazo Data Breach