CrowdSec
Incident posture
Timeline
Summary
CrowdSec confirmed that attackers stole source code from roughly 300 public and private GitHub repositories, including about 170 private repositories. The private material included source code for its SaaS console, AWS cloud routines, connectors, and automations. The company reported no leaked customer credentials or other customer-related data and said its investigation had found no token or credential that could enable lateral movement. It rotated potentially affected tokens and credentials and characterized the impact as limited to its own organization while monitoring for abnormal activity.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
CrowdSec, a French cybersecurity firm that provides open-source, crowdsourced threat intelligence and a lightweight security engine for detecting and blocking attacks targeting servers, networks, and applications, confirmed that source code was stolen from its GitHub repositories in May 2026. The company learned of the theft the week before its September 21, 2026 confirmation. CrowdSec said approximately 300 private and public repositories were compromised, including about 170 private repositories. The affected private code included the source code for CrowdSec’s SaaS console, some AWS Cloud routines, some connectors, and automations. CrowdSec stated that both private and public code was exfiltrated. The company attributed the breach to its use of a TanStack package in May 2026 during the TanStack supply chain attack, in which TeamPCP published 84 malicious artifacts across 42 TanStack packages. CrowdSec said the malware used in that campaign likely compromised an API key that allowed attackers to read its private codebase. The company said the leak likely occurred in May during the short exploitation window.
After identifying the issue, CrowdSec immediately rotated all potentially affected tokens and credentials. The company also conducted a hunt for any token, credential, or sensitive leak that could enable lateral movement and said it had found none so far. CrowdSec stated that no credentials or other types of data related to its customers were leaked. It also said the impact was limited to its own organization. CrowdSec stated that the stolen private repository code could not be used to cause harm because it could not replicate CrowdSec’s network and could only be used with its data and tools, meaning it could not be used out of context. The company said it regularly audited the SaaS source code and that the leakage should not pose an immediate threat. CrowdSec also said most of the leaked code had evolved significantly over the four months following the suspected exposure. The company said it would closely monitor for abnormal activity.
Sources
Sources available to members: 1 source.