← All stories
● Covered by 3 sources · 3 reportsLow impact2 negative1 neutral

CrowdSec Reports Source Code Leak from May 2026, Attributes to Tanstack Compromise

🔄 Updated 2d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • CrowdSec confirmed a source code leak from May 2026.
  • Private repositories for SaaS console, AWS routines, and connectors were affected.
  • No client data, PII, or sensitive credentials were leaked.
  • Tanstack compromise is the likely leak vector.
  • Attacker copied 170 private GitHub repositories on May 22.
  • CrowdSec announced the incident on September 18.
  • Leaked code appeared on an online forum on September 16.
  • Leaked data included 83 CrowdSec user email addresses.
  • Leaked data included 51 potential investor names, emails, and investment context from 2020.
  • CrowdSec's infrastructure and databases were not accessed.
  • No code was changed during the incident.
  • Malicious TanStack npm packages were published on May 11.
  • The compromise is tracked as CVE-2026-45321.
  • The copy was made with a GitHub OAuth token.
  • CrowdSec is a French cybersecurity firm.
  • CrowdSec provides open source, crowdsourced threat intelligence.
  • CrowdSec provides a lightweight security engine to detect and block attacks.
  • Approximately 300 private and public repositories were affected.

Source Code Leak Confirmed

CrowdSec announced on September 16 that it was informed of and subsequently confirmed a source code leak that occurred in May 2026. The leak involved private GitHub repositories, distinct from its public Free Open Source Software (FOSS) repositories.

Affected Code and Scope

The leaked private code includes the source for CrowdSec's SaaS console, certain AWS Cloud routines, connectors, and automations. While the news headline mentioned 300 repositories, this number includes over 130 public repositories and reflects code subdivision rather than specific volume. CrowdSec denies any "other file contained" or "internal development material" beyond the code published in these repositories. API-related information involved a token used by the CI/CD component.

No Client Data Compromised

CrowdSec emphasized that no client data, login/password, names, organizations, or other personally identifiable information (PII) were leaked, as the company does not store PII or client logs. The impact of the leak is confined to CrowdSec itself. The team conducted an immediate search for tokens, credentials, or sensitive leaks that could enable lateral movement but found none.

Limited Impact and Mitigation

The company assesses that the leaked code, while valuable, cannot significantly harm CrowdSec, as its effectiveness relies on its network effect and size. Regular audits of the SaaS source code suggest the leak should not pose an immediate threat, and most of the leaked code has evolved significantly since May 2026. CrowdSec believes using the code outside its ecosystem is unlikely due to its specific interactions with CrowdSec data and tools. All required tokens and credentials were immediately rotated to prevent future incidents.

Likely Leak Vector

CrowdSec's ongoing investigation points to the Tanstack compromise as the highly probable leak vector, similar to the Mistral AI case. This component was used by CrowdSec in May 2026 and is believed to have been backdoored to extract an API key with authorization to read the private codebase. The vulnerability was exploitable only for a short period in May 2026.

Updates

🕒 2026-09-21 · new reporting from SecurityWeek
  • CrowdSec is a French cybersecurity firm.
  • CrowdSec provides open source, crowdsourced threat intelligence.
  • CrowdSec provides a lightweight security engine to detect and block attacks.
  • Approximately 300 private and public repositories were affected.
🕒 2026-09-19 · new reporting from The Hacker News
  • Attacker copied 170 private GitHub repositories on May 22.
  • CrowdSec announced the incident on September 18.
  • Leaked code appeared on an online forum on September 16.
  • Leaked data included 83 CrowdSec user email addresses.
  • Leaked data included 51 potential investor names, emails, and investment context from 2020.
  • CrowdSec's infrastructure and databases were not accessed.
  • No code was changed during the incident.
  • Malicious TanStack npm packages were published on May 11.
  • The compromise is tracked as CVE-2026-45321.
  • The copy was made with a GitHub OAuth token.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

CrowdSec, a French cybersecurity firm, confirmed that approximately 300 of its private and public GitHub repositories had their source code stolen in May 2026 due to a supply chain attack. This incident highlights the ongoing risks of software supply chain vulnerabilities, even for security companies, and the potential for compromise through third-party packages.

CrowdSec announced that an attacker copied approximately 170 of its private GitHub repositories on May 22, using a former employee's account compromised during the TanStack npm supply chain attack. This incident highlights the risks associated with credential theft from developer machines and the importance of timely access revocation for departing employees.

CrowdSec confirmed a source code leak from May 2026 involving its private GitHub repositories, which contained code for its SaaS console, AWS routines, connectors, and automations. The company states no client data or sensitive credentials were leaked, and the incident's impact is limited to CrowdSec, with the Tanstack compromise identified as the likely vector.