CrowdSec confirms source code stolen in supply chain attack
French cybersecurity firm CrowdSec confirmed that source code was stolen from its GitHub repositories in May 2026, affecting roughly 300 repositories, about 170 of them private. The breach is linked to the TanStack supply chain attack; no customer credentials or data were leaked.
- About 300 repositories affected, including roughly 170 private ones
- Stolen code includes the SaaS console, AWS routines, connectors and automations
- Breach linked to the May 2026 attack on 42 TanStack packages
- No customer credentials or data leaked; tokens were rotated
Read next
Security