Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-20 · updated: 2026-09-20 · tags: [incident, global, supply-chain] · confidence: high · severity: high · affected_sectors: [global] · au_impact: true

French security firm CrowdSec disclosed on 18 September that an attacker copied roughly 170 of its private GitHub repositories on 22 May 2026 using the account of an employee who had just left the company. CrowdSec had kept his GitHub access open so he could finish some work, and says his laptop was compromised in May's TanStack npm supply-chain attack, in which 84 malicious versions of 42 packages (CVE-2026-45321) stole GitHub tokens, SSH keys and cloud credentials from developers' machines. On 11 May, 84 malicious versions of 42 TanStack packages were published; the copy was made 11 days later with a GitHub OAuth token from the former employee's account. The code appeared on an online forum on 16 September, together with the email addresses of 83 CrowdSec users and the names, email addresses and investment context of 51 potential investors from 2020. CrowdSec says the account was used only to copy code, that its infrastructure and databases were not accessed and no code was changed, and that the leaked material includes its web console, data science scripts and models, automation scripts and the consensus algorithm that decides which IP addresses enter its blocklists — including detection thresholds that had not previously been public. It removed the account from its GitHub organisation on 25 May, three days after the copy and months before it learned of the leak, and says GitHub support later traced the token's history to confirm the TanStack origin; its developers' machines were checked and came back clean.

Attribute Detail
**Sector Global (Macro)
**Date 2026-09-20
**Source CrowdSec
**Reliability Tier 1
**CVEs CVE-2026-45321