CrowdSec Source Code Breach: Supply Chain Security Breach Exposed
CrowdSec reports its source code was accessed through a supply chain vulnerability, impacting 300 repositories, including 170 private ones, with no customer data exposed.
Overview of the Incident
A French cybersecurity organization has disclosed that its source code was accessed through a supply chain vulnerability, affecting a significant number of repositories. The firm, which offers open-source threat intelligence and a lightweight security engine for detecting and mitigating attacks on servers, networks, and applications, confirmed the breach occurred in May 2026.
Details of the Breach
The incident involved the exfiltration of code from both private and public repositories, with approximately 300 repositories impacted, including 170 private ones. The private repositories contained source code for the company’s SaaS console, specific AWS Cloud operations, connectors, and automation scripts.
A statement from the firm noted that its team conducted an investigation to identify any tokens, credentials, or other sensitive information that could facilitate further exploitation but found no evidence of such leaks.
Impact and Response
The impact, according to CrowdSec, is confined to its internal systems. The stolen code, the company emphasized, cannot be directly exploited to cause harm. CrowdSec explained that the code is dependent on its internal infrastructure, data, and tools, making it inoperable outside its environment.
Connection to TanStack Attack
The breach is believed to stem from the May 2026 TanStack supply chain attack, in which malicious artifacts were distributed through 42 TanStack packages by an entity known as TeamPCP. CrowdSec’s use of a TanStack package during this period likely enabled attackers to compromise an API key, granting access to its private codebase.
Broader Context and Recent Incidents
In response, the company promptly revoked all potentially affected tokens and credentials. No additional details about the attackers or the full scope of the breach were provided. The incident highlights the risks associated with third-party dependencies and underscores the importance of continuous monitoring of software supply chains.
Conclusion and Security Implications
Other recent cybersecurity incidents include a data breach at Revolut involving 680 high-profile accounts and a $3 million ransom demand, a supply chain attack on Brevo that injected malware into 100,000 websites, and a Rust-based supply chain attack linked to North Korean hackers. The company’s disclosure follows a series of supply chain vulnerabilities and attacks that have targeted enterprises globally, reinforcing the need for robust security measures and proactive threat detection.
