CrowdSec Confirms Private Source Code Leak Traced to Tanstack Supply-Chain Backdoor
CrowdSec has confirmed that its private GitHub source code was exposed in a May 2026 breach, disclosed to the company on September 16. The exposed material covers the private half of its codebase — the SaaS console, some AWS cloud routines, connectors, and automations — while the public open-source Security Engine, which is published by design, is unaffected. Reports of roughly 300 leaked repositories are technically correct once the 130-plus public repos are counted, but the figure mostly reflects how finely the code is split rather than the actual volume of sensitive material.
The company stresses that the fallout is contained to CrowdSec itself. No customer data, credentials, names, or organizational details were exposed, and CrowdSec says it stores neither PII nor client logs. Its incident team searched for tokens or secrets that could enable lateral movement and reported finding none. CrowdSec argues the stolen code has limited standalone value: its effectiveness rests on network effect and scale rather than the code, the SaaS logic has changed substantially over the intervening four months, and the code only functions against CrowdSec’s own data and tooling.
The likely entry point was the compromised Tanstack component — the same vector implicated in a recent Mistral AI incident — which appears to have been backdoored to steal an API key with read access to the private repositories. The window of exploitability was short, confined to May 2026. CrowdSec says it rotated all relevant tokens and credentials immediately and will continue monitoring for anomalous activity. The disclosure is a reminder that even security vendors remain exposed to third-party developer-tooling supply-chain attacks that quietly harvest CI/CD credentials.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.