Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

CrowdSec Confirms Source Code Stolen in Supply Chain Attack

The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack.

Code supply chain attack

French cybersecurity firm CrowdSec has confirmed that approximately 300 private and public repositories were compromised and source code was stolen from them.

The company provides open source, crowdsourced threat intelligence, including a lightweight security engine to detect and block attacks targeting servers, networks, and applications.

Last week, the French outfit learned that source code had been stolen from its GitHub repositories in May 2026.

CrowdSec has confirmed the report, noting that both private and public code was exfiltrated, and that roughly 300 repositories were affected, including approximately 170 private ones.

“The private part contains the source code for our SaaS console, some AWS Cloud routines, some connectors, and automations,” the company said.

According to CrowdSec, no credentials or other types of data related to its customers were leaked, and the impact is limited to its own organization.

Advertisement. Scroll to continue reading.

“Our team quickly hunted for any token, credential, or sensitive leak that could enable lateral movement but found none so far,” it said.

Additionally, the cybersecurity firm says that, while valuable, the code stolen from its private repositories cannot be used to cause harm, as it can not replicate its network and can only be used with its data and tools; therefore, it cannot be used out of context.

“We regularly audited the SaaS source code, and its leakage shouldn’t pose an immediate threat either. Most of the leaked code has evolved significantly over those four months, but we will closely monitor for any abnormal activity,” CrowdSec says.

The data breach, it explains, was likely a direct result of the May 2026 TanStack supply chain attack, in which TeamPCP published 84 malicious artifacts across 42 TanStack packages.

Because CrowdSec used a TanStack package in May, the malware used in the campaign likely compromised an API key that allowed the attackers to read its private codebase.

The leak likely occurred in May, during the short exploitation window, and CrowdSec immediately rotated all potentially affected tokens and credentials.

Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

Related: Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Related: Rust Supply Chain Attack Linked to North Korean Hackers

Related: 23 Million User Records Compromised in Gyazo Data Breach

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Veritas Capital has appointed Joel Fulton as Chief Information Security Officer.

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.