CrowdSec Source Code Stolen via TanStack npm Supply Chain Attack: 170 Private Repositories Copied With a Stolen Token

CrowdSec Source Code Stolen via TanStack npm Supply Chain Attack: 170 Private Repositories Copied With a Stolen Token

CrowdSec Source Code Stolen via TanStack npm Supply Chain Attack: 170 Private Repositories Copied With a Stolen Token

French cybersecurity firm CrowdSec has confirmed that attackers copied source code from its GitHub repositories in May 2026 using the account of a departed employee whose laptop was compromised in the TanStack npm supply chain attack. About 170 private repositories were copied on May 22 through a GitHub OAuth token stolen from the former employee's machine, and the archive surfaced publicly on September 16 — along with the email addresses of 83 CrowdSec users and the names, email addresses, and investment context of 51 potential investors from a 2020 system.

The theft traces back to May 11, when 84 malicious versions of 42 TanStack npm packages were published — a compromise tracked as CVE-2026-45321. Installing one of those versions ran code that stole credentials from developers' machines, including GitHub tokens, SSH keys, and cloud credentials, according to TanStack's advisory.

How the Code Was Taken

CrowdSec says it kept the former employee's GitHub access open so he could finish some work. Eleven days after the malicious packages went live, an attacker used the OAuth token from his account to copy roughly 170 private repositories — code for the company's web console, AWS routines, connectors, automations, data science scripts, and the consensus algorithm that decides which IP addresses join the blocklists its users share. CrowdSec removed the account from its GitHub organization on May 25, three days after the copy and months before it learned of the leak.

The token left no trace in the GitHub logs CrowdSec could check and no longer existed by the time the leak was discovered; GitHub support later traced the token's history and confirmed the TanStack compromise as the source. CrowdSec says its infrastructure and databases were not accessed and no code was changed. The only usable credential in the leak was an AWS SNS notification token that could publish messages to a single topic — someone tried to use it on August 17 and got no further. Other tokens had already been rotated or could not be used from the internet. CrowdSec rotated exposed credentials again on September 16-17, and now runs endpoint protection on the laptops of staff who work with its code and systems, which it did not require at the time of the attack.

What the Leak Means for the Blocklist

CrowdSec's open-source Security Engine detects attacks on servers, and users who share their detections receive a shared blocklist of malicious IP addresses — infrastructure that feeds security tooling well beyond the company's own products. The leak exposed the consensus algorithm's thresholds, which had never been public. CrowdSec says poisoning the blocklist would require tens of detections from tens of trusted engines across tens of separate networks, at great cost — and that it can and does change those thresholds. The company, which says it has about 150,000 users, will contact the 83 users whose email addresses appeared, and will report the leak to the investors and to the authorities. CEO Philippe Humeau wrote to the investors that "for this I personally apologize."

CrowdSec's disclosures evolved over two days: its first statement said "no client data, login/password, name, organization, or anything else was leaked," while the follow-up report listed the 83 email addresses and the investor details. The same TanStack attack reached other companies as well — Mistral AI said a developer device was involved, and OpenAI said two employee devices were affected, with unauthorized access to a limited set of its internal code repositories.

What Should You Do?

  1. Revoke access the day someone departs. CrowdSec kept a former employee's GitHub token alive so he could "finish work" — that token was the entire breach.
  2. Treat developer laptops as credential stores. If your organization does not require endpoint protection on developer machines, this is the incident to cite.
  3. Audit secrets in repositories and shorten token lifetimes. The theft stopped at source code largely because most other credentials were already rotated or unusable — make that your default state.
  4. Pin and vet your npm dependencies. Installing a package is executing code from the internet, and TanStack's users learned that the hard way.

The WAF Angle

Two angles matter here. First, this is a supply chain attack in which every link was a trust decision made on a developer's machine — package install, credential theft, source exfiltration — a chain your WAF cannot see and your dependency-review pipeline must. Second, CrowdSec is security infrastructure: its consensus algorithm powers blocklists that feed WAFs, firewalls, and intrusion-prevention tooling worldwide. The theft exposed how those blocklists decide whom to block — a reminder to treat any single threat feed as one input among several, never an oracle. Corroborate blocklists across independent sources, and assume attackers read the same internals you do when the intel supply chain itself gets breached.

Sources