French cybersecurity company CrowdSec has recently confirmed a breach involving the theft of source code from approximately 300 repositories, affecting both private and public domains. This incident highlights the ongoing risks associated with supply chain attacks in the tech industry.
Details of the Breach
CrowdSec, known for its open-source threat intelligence services, discovered last week that their GitHub repositories had been compromised, with the breach dating back to May 2026. The company reported that around 170 of the compromised repositories were private, containing sensitive elements such as their SaaS console source code, AWS Cloud routines, and various connectors and automations.
Despite the breach’s scale, CrowdSec assured that no customer data or credentials were leaked. The impact, according to the firm, is confined to their internal systems, minimizing potential external harm.
Security Measures and Implications
Following the breach discovery, CrowdSec conducted a thorough investigation to identify any leaked tokens or credentials that could facilitate further unauthorized access. The company stated that thus far, no such vulnerabilities have been detected.
Additionally, CrowdSec emphasized that the stolen code could not be misused outside its intended environment, as it relies heavily on proprietary data and tools. The firm regularly audits its SaaS source code, further mitigating immediate threats from the leak. Continuous monitoring for unusual activities remains in place.
Connection to TanStack Supply Chain Attack
The breach was attributed to the May 2026 TanStack supply chain attack, which involved the distribution of 84 malicious artifacts across 42 TanStack packages by a group known as TeamPCP. CrowdSec’s use of one such package likely enabled the compromise of an API key, granting attackers access to private repositories.
In response, CrowdSec promptly rotated all potentially compromised tokens and credentials to prevent further unauthorized access. The incident underscores the critical need for vigilance in managing dependencies within supply chains.
This event serves as a stark reminder of the vulnerabilities inherent in software supply chains, urging cybersecurity firms and developers to adopt robust security measures to protect against similar attacks in the future.
