On May 22, CrowdSec experienced a significant security breach when an attacker copied approximately 170 of its private GitHub repositories. This incident was traced back to the account of a former employee whose laptop was compromised during a supply chain attack on TanStack. Malicious versions of TanStack's npm packages were deployed to steal credentials from developers' machines, including those from CrowdSec. The stolen code, which appeared on an online forum on September 16, included sensitive information such as email addresses of 83 users and details about 51 potential investors from 2020.
The breach was made possible by a GitHub OAuth token from the former employee's account, which was used to copy the code. CrowdSec had not disabled the employee's GitHub access immediately after their departure, though other access points had been secured. It took action to remove the account on May 25, three days after the repositories were copied. Despite the breach, CrowdSec confirmed that its infrastructure and databases remained secure, and no changes were made to the code.
The attack did not lead to any immediate damage to CrowdSec's operations. However, the leaked code did reveal several internal components, including the company's web console and data science scripts. CrowdSec has assured that the code has significantly evolved since the breach and maintains that the blocklist system it uses to identify malicious IP addresses is secure from being compromised.
In response to the incident, CrowdSec has rotated exposed credentials, implemented endpoint protection software on developers' machines, and plans to notify affected users and investors. Although the initial statement from CrowdSec minimized the impact, the September 18 report provided a more detailed account of the breach and its implications.

