Back to Feed
Supply ChainSep 21, 2026

CrowdSec Confirms Source Code Stolen in Supply Chain Attack

CrowdSec confirms source code stolen in supply chain attack via TanStack compromise.

Summary

French cybersecurity firm CrowdSec has confirmed that its GitHub repositories were compromised, resulting in the theft of source code from approximately 300 repositories, including 170 private ones. The company believes this breach was a consequence of the May 2026 TanStack supply chain attack, where malware likely exploited an API key to access CrowdSec's private codebase. CrowdSec stated that no customer data was leaked and the stolen code is unlikely to pose an immediate threat outside of its own environment.

Full text

French cybersecurity firm CrowdSec has confirmed that approximately 300 private and public repositories were compromised and source code was stolen from them. The company provides open source, crowdsourced threat intelligence, including a lightweight security engine to detect and block attacks targeting servers, networks, and applications. Last week, the French outfit learned that source code had been stolen from its GitHub repositories in May 2026. CrowdSec has confirmed the report, noting that both private and public code was exfiltrated, and that roughly 300 repositories were affected, including approximately 170 private ones. “The private part contains the source code for our SaaS console, some AWS Cloud routines, some connectors, and automations,” the company said. According to CrowdSec, no credentials or other types of data related to its customers were leaked, and the impact is limited to its own organization.Advertisement. Scroll to continue reading. “Our team quickly hunted for any token, credential, or sensitive leak that could enable lateral movement but found none so far,” it said. Additionally, the cybersecurity firm says that, while valuable, the code stolen from its private repositories cannot be used to cause harm, as it can not replicate its network and can only be used with its data and tools; therefore, it cannot be used out of context. “We regularly audited the SaaS source code, and its leakage shouldn’t pose an immediate threat either. Most of the leaked code has evolved significantly over those four months, but we will closely monitor for any abnormal activity,” CrowdSec says. The data breach, it explains, was likely a direct result of the May 2026 TanStack supply chain attack, in which TeamPCP published 84 malicious artifacts across 42 TanStack packages. Because CrowdSec used a TanStack package in May, the malware used in the campaign likely compromised an API key that allowed the attackers to read its private codebase. The leak likely occurred in May, during the short exploitation window, and CrowdSec immediately rotated all potentially affected tokens and credentials. Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom Related: Brevo Supply Chain Attack Injects Malware Into 100,000 Websites Related: Rust Supply Chain Attack Linked to North Korean Hackers Related: 23 Million User Records Compromised in Gyazo Data Breach Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire NightmareStresser DDoS Service Disrupted in International OperationBrevo Supply Chain Attack Injects Malware Into 100,000 WebsitesCritical Orkes Conductor Vulnerability Exploited in AttacksMIND Secures $72 Million for AI-Powered DLPRevolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M RansomComp AI Raises $34 Million for AI-Native Compliance and SecurityISC Patches 14 Vulnerabilities in BIND 9 Security UpdateCisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard Latest News Colorado Water Utilities Hit by Cyberattacks Targeting OT SystemsOrganizations Warned of 3 Exploited Linux Kernel VulnerabilitiesGoogle Confirms Gemini AI Breached Three FirmsTigerByte Cyber Emerges From Stealth With $3 Million in FundingIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawAI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code23 Million User Records Compromised in Gyazo Data Breach Microsoft Patches 18 Vulnerabilities in AI, Cloud Products Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveVeritas Capital has appointed Joel Fulton as Chief Information Security Officer.incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Entities

CrowdSec (vendor)TanStack (product)TeamPCP (threat_actor)GitHub (technology)