CrowdSec has disclosed that an attacker copied around 170 of its private GitHub repositories following a supply chain attack involving malicious TanStack npm packages. The French cybersecurity company said the incident occurred on May 22 after an attacker accessed the GitHub account of a former employee whose access permissions had remained active to complete pending work. CrowdSec stated that the affected account was used only to copy source code and that its infrastructure, databases, and code repositories were not modified during the incident. According to CrowdSec’s investigation, the employee’s laptop was compromised during the TanStack npm supply chain attack reported in May. The incident involved malicious versions of TanStack npm packages that were designed to steal credentials from developer machines, including GitHub tokens, SSH keys, and cloud credentials. The compromise was tracked as CVE-2026-45321 after 84 malicious versions of 42 TanStack npm packages were published on May 11. CrowdSec said the copied code later appeared on an online forum on September 16, along with email addresses of 83 CrowdSec users and names, email addresses, and investment details of 51 potential investors from 2020.
CrowdSec explained that the attacker used a GitHub OAuth token connected to the former employee’s account to access and copy the repositories 11 days after the malicious packages were published. The company had kept the employee’s GitHub access active temporarily to allow completion of work-related tasks. CrowdSec removed the account from its GitHub organization on May 25, three days after the copying activity occurred and several months before discovering the exposure. The company said other access permissions had already been removed, which helped explain why no suspicious activity was detected in its AWS environment. GitHub support later assisted with tracing the token history and confirmed the connection to the TanStack-related compromise. CrowdSec noted that it did not identify which malicious package reached the employee’s device or when it was installed, while internal checks of developers’ machines showed no ongoing compromise.
The exposed repositories contained source code related to CrowdSec’s web console, data science scripts and models, automation tools, and the consensus algorithm used by its Security Engine to determine which IP addresses are added to shared blocklists. CrowdSec said the leaked code was almost four months old and had undergone significant changes since the exposed version. The company also noted that the leak revealed some internal thresholds used by the consensus algorithm, although it believes the blocklist system cannot be easily manipulated. According to CrowdSec, an attacker would require activity from multiple trusted engines across different networks to influence the system, making such an attempt difficult and costly. The company added that it can adjust these thresholds as part of its security operations. CrowdSec stated that the only potentially usable credential found in the leaked material was related to Amazon Web Services Simple Notification Service (SNS), and it was limited to publishing messages to a single topic. The company said someone attempted to use the credential on August 17 but was unsuccessful. Other exposed tokens had either already been rotated or were not usable through internet access. CrowdSec rotated affected credentials on September 16 and 17 and has since introduced endpoint protection software on employee devices involved with code and infrastructure access.
The company said it plans to contact affected users whose email addresses were exposed and notify investors whose details appeared in the leaked material. CrowdSec estimated that it has around 150,000 users and said the exposed user email addresses were retained by its data science team for product research purposes. The investor information came from an older 2020 system that was not intended for public access, and CrowdSec said it would report the matter to relevant authorities and affected parties. The latest disclosure differs from CrowdSec’s initial statement released a day earlier, where the company said the impact was limited to its own systems and that no client information had been exposed. The updated report clarified that user email addresses and investor details were included in the copied material. CrowdSec also revised its explanation of the attack path, stating that the exposure occurred through the compromised former employee account rather than finding malicious TanStack packages directly within its code repositories. The incident highlights ongoing security challenges around software supply chains, developer credentials, and access management practices in modern technology environments.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.