CrowdSec Confirms Source Code Leak After Former Employee’s Account Was Abused

CrowdSec confirmed that approximately 170 private repositories were copied through an OAuth token belonging to a former employee’s account. The company reports no evidence of code changes or access to production infrastructure.

CrowdSec’s code leak was confirmed in a forensic report published on September 18. The company responded to an archive of source code that appeared on September 16. According to the company, an attacker copied approximately 170 private repositories from GitHub on May 22 using an OAuth token belonging to a former employee’s account.

CrowdSec links the incident to the May compromise of the TanStack project’s npm packages. According to TanStack, developer credentials were affected at the time and may later have been used to access other systems or repositories.

Investigation says CrowdSec code leak was limited to cloning

According to CrowdSec, its investigation, conducted with GitHub, showed that the compromised account was used only to clone repositories. The company says it found no commits or changes to source code, infrastructure, or continuous integration and deployment (CI) systems.

CrowdSec also claims that its databases and company infrastructure were not compromised. This finding is based on the company’s internal investigation and cannot be fully verified externally. Active exploitation of the CrowdSec product or access to its production infrastructure has also not been confirmed.

According to CrowdSec, the published archive also contained limited personal data: the email addresses of 83 users and information about 51 prospective investors from 2020. The company also stated that the affected AWS token had narrowly limited permissions. According to its findings, an attempt to verify it did not progress further.

Link to the compromised TanStack packages

In May, TanStack confirmed the compromise of 42 npm packages in 84 malicious versions. The affected versions were removed or revoked, and the project described the versions currently available as safe. GitHub’s official security advisory describes malware designed to steal credentials.

The CrowdSec case highlights the delay with which the consequences of compromised dependencies can emerge. Organizations that used the affected TanStack versions on May 11 should review available credentials and rotate them as needed.

The identity of the person or group that downloaded the repositories has not been independently confirmed. CrowdSec attributes the activity to an account using the name “diencracked” and links it to BreachForums. The attribution of the entire attack chain to TeamPCP/UNC6780 is also a claim by CrowdSec; no independent confirmation from law enforcement authorities or GitHub is publicly available.

What happens next

Key points to watch include any results from reports of the personal-data leak, further evidence of misuse of the leaked code, or access beyond repository cloning. Independent confirmation of the attacker’s identity and any possible connection to the campaign against TanStack will also be important.

Sources

Verified and updated: 09/20/2026 06:21

Sharing