CrowdSec announced on September 16 that it was informed of and subsequently confirmed a source code leak that occurred in May 2026. The leak involved private GitHub repositories, distinct from its public Free Open Source Software (FOSS) repositories.
The leaked private code includes the source for CrowdSec's SaaS console, certain AWS Cloud routines, connectors, and automations. While the news headline mentioned 300 repositories, this number includes over 130 public repositories and reflects code subdivision rather than specific volume. CrowdSec denies any "other file contained" or "internal development material" beyond the code published in these repositories. API-related information involved a token used by the CI/CD component.
CrowdSec emphasized that no client data, login/password, names, organizations, or other personally identifiable information (PII) were leaked, as the company does not store PII or client logs. The impact of the leak is confined to CrowdSec itself. The team conducted an immediate search for tokens, credentials, or sensitive leaks that could enable lateral movement but found none.
The company assesses that the leaked code, while valuable, cannot significantly harm CrowdSec, as its effectiveness relies on its network effect and size. Regular audits of the SaaS source code suggest the leak should not pose an immediate threat, and most of the leaked code has evolved significantly since May 2026. CrowdSec believes using the code outside its ecosystem is unlikely due to its specific interactions with CrowdSec data and tools. All required tokens and credentials were immediately rotated to prevent future incidents.
CrowdSec's ongoing investigation points to the Tanstack compromise as the highly probable leak vector, similar to the Mistral AI case. This component was used by CrowdSec in May 2026 and is believed to have been backdoored to extract an API key with authorization to read the private codebase. The vulnerability was exploitable only for a short period in May 2026.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
CrowdSec, a French cybersecurity firm, confirmed that approximately 300 of its private and public GitHub repositories had their source code stolen in May 2026 due to a supply chain attack. This incident highlights the ongoing risks of software supply chain vulnerabilities, even for security companies, and the potential for compromise through third-party packages.
CrowdSec announced that an attacker copied approximately 170 of its private GitHub repositories on May 22, using a former employee's account compromised during the TanStack npm supply chain attack. This incident highlights the risks associated with credential theft from developer machines and the importance of timely access revocation for departing employees.
CrowdSec confirmed a source code leak from May 2026 involving its private GitHub repositories, which contained code for its SaaS console, AWS routines, connectors, and automations. The company states no client data or sensitive credentials were leaked, and the incident's impact is limited to CrowdSec, with the Tanstack compromise identified as the likely vector.