NewsTradingSentimentCalendarCommunityBriefing
Tech

Former Employee Account Used to Steal CrowdSec Code

By Tech Desk · 2026-09-19 · 2 min read
A broken padlock hanging from a chain against a dark background
Illustration: Tradingbird

A supply chain attack on npm packages enabled the theft of 170 private repositories from CrowdSec. The breach exposed internal logic and user data months before detection.

CrowdSec, a French security firm, disclosed on September 18 that an attacker copied approximately 170 of its private GitHub repositories on May 22. The intrusion occurred through the account of an employee who had recently left the company. CrowdSec had retained this individual's access permissions to allow them to complete final work tasks, a decision that ultimately facilitated the breach.

The attack vector traces back to a compromise in the TanStack ecosystem. Malicious versions of npm packages stole credentials from the former employee's laptop, including GitHub tokens. These stolen credentials allowed the attacker to access private code repositories. The stolen data was later posted on an online forum on September 16, revealing source code and personal information.

Supply Chain Attack Enabled Credential Theft

On May 11, attackers published 84 malicious versions of 42 TanStack npm packages. This incident, tracked as CVE-2026-45321, executed code that harvested credentials from developers' machines. According to TanStack's advisory, the stolen data included GitHub tokens, SSH keys, and cloud credentials. Eleven days later, the attacker used a GitHub OAuth token from the former employee's account to copy the repositories.

CrowdSec removed the employee's account from its GitHub organization on May 25, three days after the copy event. The company had already revoked other access rights, which explains why no suspicious activity appeared in its AWS systems. The specific token used for the leak left no trace in standard GitHub logs and had expired by the time the breach was detected. GitHub support later traced the token's history, confirming the TanStack attack as the source.

Sensitive Algorithms and Personal Data Exposed

The leaked code included CrowdSec's web console, data science scripts, and the consensus algorithm that determines which IP addresses are added to shared blocklists. This algorithm's thresholds, such as the number of detections required to block an IP, had not been previously public. The leak also exposed email addresses of 83 users and investment details of 51 potential investors from 2020.

The company states that the code is nearly four months old and has undergone significant changes since the theft. CrowdSec assesses that the blocklist remains secure against poisoning, noting that an attacker would need to generate tens of detections from trusted engines across separate networks, a costly and complex endeavor. The firm can adjust its thresholds as needed to maintain security.

Limited Impact on Active Infrastructure

CrowdSec reports that its infrastructure and databases were not accessed, and no code was altered. The only usable credential found in the leak was for AWS's SNS notification service, which could only publish to a single topic. An attempted use of this credential on August 17 failed to proceed further. Other tokens were rotated or inaccessible from the internet.

The incident is part of a broader wave of attacks affecting multiple companies, including Mistral AI and OpenAI, which reported similar compromises of employee devices. CrowdSec, which serves approximately 150,000 users, plans to contact affected users and report the leak to investors. The Hacker News reported that the company is taking steps to mitigate the impact of this significant security breach.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories