Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

CrowdSec's Data Breach: A Cautionary Tale of Supply Chain Security Vulnerabilities


CrowdSec, a French security company, has revealed that a private GitHub repository containing sensitive information was compromised due to a vulnerability in one of its TanStack npm packages. The breach highlights the importance of robust security measures to protect supply chains and underscores the need for regular security audits and vulnerability assessments.

  • A private GitHub repository containing sensitive information was compromised due to a vulnerability in a TanStack npm package.
  • An attacker was able to steal credentials from developers' machines, including GitHub tokens, SSH keys, and cloud credentials.
  • A former employee with open GitHub access was responsible for the breach, exploiting a vulnerability that left no trace in the GitHub logs.
  • CrowdSec has implemented endpoint protection software on staff laptops and conducted regular security audits and vulnerability assessments to prevent similar breaches.
  • The breach highlights the need for companies to prioritize their security posture and take proactive measures to protect their supply chains.



  • In a concerning development that highlights the complexities of supply chain security, CrowdSec, a French security company, recently revealed that a private GitHub repository containing sensitive information was compromised due to a vulnerability in one of its TanStack npm packages. The breach, which occurred in May, saw an attacker copy approximately 170 of CrowdSec's private GitHub repositories, including its web console, data science scripts and models, automation scripts, and the consensus algorithm that determines which IP addresses are added to the blocklist.

    The attack, which was traced back to a TanStack npm package, exploited a vulnerability that allowed an attacker to steal credentials from developers' machines, including GitHub tokens, SSH keys, and cloud credentials. The malicious code was published on an online forum in September, where it contained the email addresses of 83 CrowdSec users and the names, email addresses, and investment context of 51 potential investors from 2020.

    The breach was attributed to a former employee who had left the company, whose GitHub access was kept open by CrowdSec. The employee's laptop was compromised in May's supply chain attack on TanStack, which also affected other companies, including Mistral AI and OpenAI. The compromised employee used a GitHub OAuth token to copy the code, which left no trace in the GitHub logs and no longer existed when CrowdSec learned of the leak.

    CrowdSec's report highlights the need for companies to implement robust security measures to protect their supply chains. The company had not required endpoint protection software on developers' machines at the time, but it now runs such software on the laptops of staff who work with its code or systems. The breach also underscores the importance of regular security audits and vulnerability assessments to identify potential weaknesses before they can be exploited.

    The leaked code revealed several sensitive details about CrowdSec's security measures, including the thresholds used by its consensus algorithm. The company stated that the blocklist, which is used to prevent malicious IP addresses from being added, still cannot be poisoned, meaning tricked into blocking a harmless IP address. However, CrowdSec noted that an attacker would need tens of detections from tens of trusted engines across tens of separate networks, at great cost, to successfully poison the blocklist.

    In response to the breach, CrowdSec has contacted the affected users and investors and reported the leak to the authorities. The company has also rotated the exposed credentials and taken steps to improve its security measures. The incident serves as a reminder to companies to prioritize their security posture and take proactive measures to protect their supply chains.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/CrowdSecs-Data-Breach-A-Cautionary-Tale-of-Supply-Chain-Security-Vulnerabilities-ehn.shtml

  • https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html


  • Published: Sat Sep 19 04:11:39 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us