French cybersecurity firm CrowdSec has confirmed that approximately 300 private and public repositories were compromised and source code was stolen from them.
The company provides open source, crowdsourced threat intelligence, including a lightweight security engine to detect and block attacks targeting servers, networks, and applications.
Last week, the French outfit learned that source code had been stolen from its GitHub repositories in May 2026.
CrowdSec has confirmed the report, noting that both private and public code was exfiltrated, and that roughly 300 repositories were affected, including approximately 170 private ones.
“The private part contains the source code for our SaaS console, some AWS Cloud routines, some connectors, and automations,” the company said.
According to CrowdSec, no credentials or other types of data related to its customers were leaked, and the impact is limited to its own organization.
“Our team quickly hunted for any token, credential, or sensitive leak that could enable lateral movement but found none so far,” it said.
Additionally, the cybersecurity firm says that, while valuable, the code stolen from its private repositories cannot be used to cause harm, as it can not replicate its network and can only be used with its data and tools; therefore, it cannot be used out of context.
“We regularly audited the SaaS source code, and its leakage shouldn’t pose an immediate threat either. Most of the leaked code has evolved significantly over those four months, but we will closely monitor for any abnormal activity,” CrowdSec says.
The data breach, it explains, was likely a direct result of the May 2026 TanStack supply chain attack, in which TeamPCP published 84 malicious artifacts across 42 TanStack packages.
Because CrowdSec used a TanStack package in May, the malware used in the campaign likely compromised an API key that allowed the attackers to read its private codebase.
The leak likely occurred in May, during the short exploitation window, and CrowdSec immediately rotated all potentially affected tokens and credentials.
Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related: Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Related: Rust Supply Chain Attack Linked to North Korean Hackers
Related: 23 Million User Records Compromised in Gyazo Data Breach
