CrowdSec Acknowledges Massive Source Code Leak

CrowdSec source code leak and TanStack supply chain attack details

The prominent cybersecurity firm CrowdSec recently acknowledged a significant data breach. Attackers successfully exfiltrated source code from approximately 170 private GitHub repositories. A malicious actor initially duplicated this proprietary code on May 22, 2026. The perpetrator utilized the compromised account of a recently departed developer. Shockingly, the company remained entirely oblivious to this severe incident until September 16. The alarming truth finally emerged when the stolen archive materialized on a notorious hacking forum.

Tracing the Speedy Exfiltration Process

According to CrowdSec’s comprehensive internal investigation, the massive data exfiltration required just over nine minutes. Specifically, the theft occurred between 05:52:29 and 06:01:33 UTC. Beyond the 170 confidential repositories, the illicit archive also contained over 130 public repositories. Therefore, widespread reports mentioning roughly 300 compromised repositories are technically accurate. However, a substantial portion of this specific code was already publicly accessible beforehand.

The paramount concern naturally revolves around the highly sensitive private data. The stolen archive included the foundational source code for the CrowdSec SaaS console. Furthermore, it contained various AWS cloud procedures, specialized connectors, automation scripts, and sophisticated data processing models. It also exposed internal components crucial to their proprietary IP address reputation system. Nevertheless, the company vehemently asserts that the intruder never gained access to core infrastructure or databases. The attacker did not alter any existing source code or disrupt established CI/CD pipelines.

Unraveling the Intrusion Methodology

Digital footprints left within the stolen archive ultimately illuminated the attacker’s entry method. A specific Git configuration file retained a URL prominently featuring a compromised OAuth token beginning with “gho_”. Subsequently, GitHub provided CrowdSec with crucial activity logs corresponding to the precise incident timeframe. Using this evidence, the company conclusively linked the massive cloning operation to a specific developer’s account. This particular employee had departed CrowdSec shortly before the breach occurred.

Management had previously revoked the vast majority of this former employee’s corporate access rights. However, they temporarily maintained the developer’s access to the CrowdSec GitHub organization. The separation was entirely amicable, and the developer simply requested temporary access to complete unfinished tasks. Consequently, administrators completely removed the account from the GitHub organization on May 25. This removal happened precisely three days after the unauthorized repository cloning occurred. At that time, CrowdSec still had absolutely no knowledge of the silent data leak.

The Role of the TanStack Supply Chain Attack

The cybersecurity firm theorizes that adversaries stole the critical OAuth token directly from the developer’s personal machine. This theft likely stemmed from the notorious TanStack supply chain attack that occurred earlier in May. On May 11, malicious actors unleashed 84 severely compromised versions of 42 distinct @tanstack/* packages directly onto the npm registry. This embedded malware actively harvested GitHub tokens, SSH keys, and AWS and GCP credentials. It also targeted Kubernetes, Vault, and npm tokens, subsequently transmitting these invaluable secrets to external command servers.

TanStack officially corroborated the existence of these 84 malicious versions. They published a detailed postmortem confirming that these dangerous packages appeared within a brief window on May 11. Fortunately, administrators swiftly purged the infected packages from active circulation. During its subsequent rigorous audits, CrowdSec found absolutely no trace of these compromised TanStack versions within its own repository history. Therefore, the company firmly concludes that the initial compromise occurred on the former developer’s local machine, entirely outside CrowdSec’s secure build infrastructure.

The Threat of Stolen Access Tokens

This unsettling incident powerfully highlights a terrifying reality regarding stolen access tokens. Traditional security measures like two-factor authentication (2FA), hardware security keys, and complex passwords become completely useless if an attacker possesses a valid token granting sufficient privileges. CrowdSec emphasized its strict reliance on 2FA, passkeys, and physical security keys. Nevertheless, the active OAuth token granted the intruder unfettered ability to read private repositories without triggering any new interactive authorization requests.

The exhaustive investigation uncovered yet another active secret hidden within the exfiltrated code. An AWS token granted strictly limited access to the SNS notification service, allowing message publication to only a single, specific topic. Unknown individuals probed this token’s permissions on August 17, nearly three months after the initial repository theft. Fortunately, CrowdSec confidently asserts that the attackers achieved absolutely no further lateral movement through the infrastructure using this specific token.

Reassessing the Impact on Personal Data

The final investigative report also necessitated a crucial revision regarding the initial assessment of personal data exposure. Originally, CrowdSec confidently proclaimed that no names or user data had leaked. However, deeper scrutiny revealed the email addresses of 83 specific users. The Data Science team previously utilized these addresses for detailed product performance analysis. The compromised archive also inadvertently included the names, email addresses, and investment contexts of 51 potential investors dating back to 2020. Consequently, the company formally pledged to notify all affected individuals and the relevant regulatory authorities immediately.

Crucially, CrowdSec found absolutely no customer passwords or client logs within the stolen archive. They found no sensitive data that would permit direct, unauthorized access to user accounts. The company also confirmed finding no evidence suggesting any malicious modification of published software or the compromise of production infrastructure. Thus, the only confirmed consequence remains the unauthorized copying of private source code and a strictly limited set of associated data.

Following this severe incident, CrowdSec immediately mandated Endpoint Detection and Response (EDR) software installation on all employee workstations interacting with code and infrastructure. They significantly strengthened their package monitoring protocols and resolved to completely overhaul their account deactivation procedures for departing employees. The situation involving the former developer proved especially instructive. While management formally retained the access briefly for seemingly logical reasons, those nine unmonitored minutes provided the attacker ample time to extract nearly the entire proprietary codebase. Ultimately, it took the company a staggering 117 days to even realize the catastrophic theft had occurred.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply