www.securityweek.com 21 Sept 2026, 10:55 UTC

CrowdSec Reveals 300 GitHub Repositories Breached in Supply Chain Attack

CrowdSec Reveals 300 GitHub Repositories Breached in Supply Chain Attack
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

FRENCH cybersecurity firm CrowdSec has confirmed that attackers compromised about 300 of its GitHub repositories in May 2026 and stole source code, including roughly 170 private repositories. The exposed private material covered code for its SaaS console, AWS routines, connectors and automations. CrowdSec said no customer credentials or other customer data were leaked and that the impact is confined to its own organisation.

The company believes the incident resulted from the May 2026 TanStack supply-chain attack, during which TeamPCP published 84 malicious artefacts across 42 TanStack packages. CrowdSec had used a TanStack package, and the malware apparently compromised an API key that allowed attackers to read its private codebase. The code was likely taken during the campaign’s short exploitation window.

CrowdSec said it promptly rotated potentially affected tokens and credentials, and found no token, credential or other sensitive material that could enable lateral movement.

CrowdSec said the stolen private code cannot independently be used to cause harm because it cannot replicate the company’s network and requires its data and tools. It added that much of the code had changed substantially over the following four months, while warning that it will continue monitoring for abnormal activity.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline