On September 18, CrowdSec, a French cybersecurity company, disclosed a significant data breach incident that occurred on May 22 when an attacker exploited the GitHub account of a recently departed employee. This unauthorized access allowed for the copying of approximately 170 private repositories, raising alarms about sensitive information being compromised.
The breach originated from a supply chain attack on TanStack, identified as a critical incident in May, where JavaScript package managers distributed malicious versions of npm packages, allowing attackers to retrieve credentials from developers’ machines. CrowdSec had inadvertently kept the former employee’s GitHub access active, which enabled the attacker to leverage a GitHub OAuth token from the employee’s account to facilitate the illicit copying of code.
The stolen data surfaced on an online forum on September 16, revealing not only the source code from CrowdSec’s repositories but also personal information, including the email addresses of 83 users and details of 51 potential investors from earlier years. Despite this troubling breach, CrowdSec maintained that its infrastructure and databases remained secure, and no modifications were made to the codebase.
According to CrowdSec’s analysis, the incident can be attributed to the compromise tracked as CVE-2026-45321, linked to the malicious npm packages. The exploitation allowed the attacker to collect sensitive credentials, including GitHub tokens, SSH keys, and cloud service credentials, from the employee’s compromised machine. The company removed the employee’s GitHub permissions shortly after the incident, three days post-breach, suggesting that they believed to have mitigated additional risks.
CrowdSec emphasized that, while the token used in the breach left no visible traces in logs, GitHub support subsequently traced its origins back to the TanStack attack. The company did not disclose specifics on which malicious packages could have accessed the employee’s device, nor did they include insights from GitHub’s concurrent findings. The developers’ machines were reportedly checked and cleared of any suspicious activity.
The breach also provided insights into CrowdSec’s internal practices, revealing the thresholds used within their consensus algorithm for updating their blocklists. The leaked information, described as nearly four months outdated, nonetheless poses risks related to the potential for future exploitation. CrowdSec reassured stakeholders that its blocklist remains resilient against poisoning attempts by malicious actors.
The data breach incident also implicated other organizations, with Mistral AI and OpenAI noting similar unauthorized access incidents. It underscores the pervasive threat of supply chain vulnerabilities impacting a wide range of tech firms.
CrowdSec’s response has evolved, acknowledging a substantial breach of sensitive information while initially maintaining that client data was unaffected. It has committed to informing affected investors and relevant authorities, reflecting a proactive approach to rectify the damage caused by the incident.
In conclusion, this event serves as a stark reminder of the vulnerabilities inherent within software supply chains and the critical importance of stringent access controls. The incident exemplifies tactics listed in the MITRE ATT&CK framework, such as initial access through credential dumping and the potential for persistence via compromised accounts, highlighting the complexities of ensuring cybersecurity in an increasingly interconnected software ecosystem.