An unauthorized individual accessed approximately 170 private GitHub repositories belonging to CrowdSec on May 22. This breach was facilitated using the account of a recently departed employee, CrowdSec disclosed on September 18.
Incident Details and Initial Response
The security firm, based in France, initially retained the former employee’s GitHub access. In May, his laptop was compromised during a supply chain attack involving TanStack’s npm packages, which were altered to pilfer credentials from developers’ systems. The stolen code surfaced on an online forum on September 16, revealing source code alongside the email addresses of 83 users and information about 51 prospective investors from 2020, according to CrowdSec.
CrowdSec confirmed that the account was solely used for code copying. Their infrastructure and databases were unharmed, and the code itself remained unchanged.
Understanding the Vulnerability
The attack’s origins trace back to May 11, when 84 tainted versions of 42 TanStack npm packages were released, linked to CVE-2026-45321. Installing any of these versions triggered credential theft, including GitHub tokens and SSH keys, as per TanStack’s advisory.
Eleven days post-release, the repositories were copied using a GitHub OAuth token from the former employee’s account. Despite the copy occurring three days before his access was revoked, CrowdSec only discovered the breach months later. No suspicious activity was detected in their AWS systems due to preemptive access revocations.
The token, now non-existent, left no trace in GitHub logs. GitHub support later confirmed TanStack as the breach’s source. CrowdSec did not specify which malicious package affected the former employee’s device, nor did the report include GitHub’s findings.
Impact and Future Implications
The breach affected not only CrowdSec but also other companies like Mistral AI and OpenAI, whose employees’ devices were similarly compromised, granting unauthorized access to select internal code repositories.
The leaked archive contained sensitive components from CrowdSec’s private repositories, not their public Security Engine. This includes web console code, data science scripts, and a consensus algorithm for blocklisting malicious IPs. The leaked code, however, is outdated and has undergone significant changes since.
Despite concerns, CrowdSec asserts that the blocklist cannot be easily manipulated. The attacker would need substantial resources across trusted networks to achieve this. CrowdSec has also swiftly rotated the exposed AWS SNS credentials and enhanced security measures by implementing endpoint protection software on developers’ machines.
Looking ahead, CrowdSec plans to notify affected users and investors and report the incident to relevant authorities. CEO Philippe Humeau personally apologized to investors for the breach. The company’s proactive measures aim to prevent future occurrences.
