CrowdSec Confirms Source Code Leak After Former Employee’s Account Was Abused
CrowdSec confirmed that approximately 170 private repositories were copied through an OAuth token belonging to a former employee’s account. The company reports no evidence of code changes or access to production infrastructure.

CrowdSec’s code leak was confirmed in a forensic report published on September 18. The company responded to an archive of source code that appeared on September 16. According to the company, an attacker copied approximately 170 private repositories from GitHub on May 22 using an OAuth token belonging to a former employee’s account.
CrowdSec links the incident to the May compromise of the TanStack project’s npm packages. According to TanStack, developer credentials were affected at the time and may later have been used to access other systems or repositories.
Investigation says CrowdSec code leak was limited to cloning
According to CrowdSec, its investigation, conducted with GitHub, showed that the compromised account was used only to clone repositories. The company says it found no commits or changes to source code, infrastructure, or continuous integration and deployment (CI) systems.
CrowdSec also claims that its databases and company infrastructure were not compromised. This finding is based on the company’s internal investigation and cannot be fully verified externally. Active exploitation of the CrowdSec product or access to its production infrastructure has also not been confirmed.
According to CrowdSec, the published archive also contained limited personal data: the email addresses of 83 users and information about 51 prospective investors from 2020. The company also stated that the affected AWS token had narrowly limited permissions. According to its findings, an attempt to verify it did not progress further.
Link to the compromised TanStack packages
In May, TanStack confirmed the compromise of 42 npm packages in 84 malicious versions. The affected versions were removed or revoked, and the project described the versions currently available as safe. GitHub’s official security advisory describes malware designed to steal credentials.
The CrowdSec case highlights the delay with which the consequences of compromised dependencies can emerge. Organizations that used the affected TanStack versions on May 11 should review available credentials and rotate them as needed.
The identity of the person or group that downloaded the repositories has not been independently confirmed. CrowdSec attributes the activity to an account using the name “diencracked” and links it to BreachForums. The attribution of the entire attack chain to TeamPCP/UNC6780 is also a claim by CrowdSec; no independent confirmation from law enforcement authorities or GitHub is publicly available.
What happens next
Key points to watch include any results from reports of the personal-data leak, further evidence of misuse of the leaked code, or access beyond repository cloning. Independent confirmation of the attacker’s identity and any possible connection to the campaign against TanStack will also be important.
Sources
- CrowdSec – TanStack Supply Chain Attack Analysis – CrowdSec confirms the scope of the leak, the timing of the repository cloning, misuse of a former employee’s account, the state of the infrastructure, and remediation steps.
- TanStack – Postmortem: TanStack npm supply-chain compromise – TanStack documents the May compromise of 42 packages, the malicious versions, the attack mechanism, and their removal.
- GitHub Security Advisory GHSA-g7cv-rxg3-hmpx – The official advisory identifies the affected TanStack packages and the nature of the credential-stealing malware.
- Fuites Infos – CrowdSec détaille la fuite de son code source – Independently documents that information about the publication of the leaked-code archive appeared on September 16.
Verified and updated: 09/20/2026 06:21



