news.mlab.sh
Back to the feed
supply-chain

CrowdSec Confirms Source Code Stolen in Supply Chain Attack

Medium
Summary

French cybersecurity firm CrowdSec experienced a supply chain attack resulting in the theft of source code from its GitHub repositories. The attack stemmed from the May 2026 TanStack supply chain attack, leading to the exfiltration of code including their SaaS console and AWS Cloud routines. While the stolen code is largely outdated and unusable outside of CrowdSec’s environment, the firm has taken steps to mitigate potential risks.

French cybersecurity firm CrowdSec recently confirmed that a supply chain attack had compromised its GitHub repositories, leading to the theft of approximately 300 private and public repositories. The attack was directly linked to the May 2026 TanStack supply chain attack, where TeamPCP published 84 malicious artifacts across 42 TanStack packages.

CrowdSec’s private repositories contained source code for their SaaS console, AWS Cloud routines, and various connectors. The company stated that no customer credentials or sensitive data were leaked during the incident.

“Our team quickly hunted for any token, credential, or sensitive leak that could enable lateral movement but found none so far,” CrowdSec reported.

They emphasized that the stolen code is largely outdated and cannot be used to cause harm outside of CrowdSec’s environment due to its reliance on specific data and tools.

“We regularly audited the SaaS source code, and its leakage shouldn’t pose an immediate threat either. Most of the leaked code has evolved significantly over those four months,” the company added.

CrowdSec immediately rotated all potentially affected tokens and credentials following the incident. The firm is closely monitoring for any abnormal activity related to the compromised code.

Read the full article at SecurityWeek