CrowdSec Confirms Source Code Stolen in Supply Chain Attack

CrowdSec Confirms Source Code Stolen in Supply Chain Attack, Impact Limited to Its Own Organization

In a shocking revelation, French cybersecurity firm CrowdSec has confirmed that its source code was stolen from its GitHub repositories in May 2026. The company, which provides open-source threat intelligence and a lightweight security engine to detect and block attacks, revealed that approximately 300 private and public repositories were compromised, including around 170 private ones.

According to CrowdSec, the stolen code includes sensitive information such as source code for its SaaS console, AWS Cloud routines, connectors, and automations. However, the company claims that no customer credentials or other types of data related to its customers were leaked, limiting the impact to its own organization. The cybersecurity firm’s investigation suggests that the breach was likely a direct result of the May 2026 TanStack supply chain attack, in which malicious artifacts were published across 42 packages.

The stolen code, while valuable, cannot be used to cause harm as it requires CrowdSec’s network and data to function. Moreover, the company had regularly audited its SaaS source code, making the leaked information less threatening. Nonetheless, CrowdSec is closely monitoring for any abnormal activity and has taken steps to mitigate potential risks.

The incident highlights the growing threat of supply chain attacks, which involve compromising a software package or component to gain unauthorized access to sensitive data. In this case, the attackers likely exploited an API key that allowed them to read CrowdSec’s private codebase during the short exploitation window in May 2026. The company immediately rotated all potentially affected tokens and credentials after discovering the breach.

The TanStack supply chain attack is a significant concern for cybersecurity professionals as it demonstrates how easily malicious artifacts can be introduced into widely used packages, putting numerous organizations at risk. CrowdSec’s experience serves as a cautionary tale about the importance of monitoring dependencies, regularly updating software components, and implementing robust security measures to prevent similar breaches.

As a takeaway from this incident, it is essential for companies to maintain vigilant supply chain security practices, including frequent audits, monitoring of dependencies, and prompt remediation in case of any detected vulnerabilities. By staying proactive and informed about potential threats, organizations can minimize their exposure to supply chain attacks and protect sensitive data.


Source: SecurityWeek — 2026-09-21