CrowdSec Confirms Source Code Stolen in Breach
The company reported that both public and private source code were exfiltrated in a breach originating from a compromised API key. No customer data or credentials were affected.

The Scope of the Incident
French cybersecurity firm CrowdSec has officially confirmed that its internal systems were the target of a data breach. The incident resulted in the unauthorized access and exfiltration of source code from approximately 300 of its GitHub repositories. It has been confirmed that this total includes roughly 170 private repositories, which contained sensitive infrastructure components including the company’s SaaS console, AWS Cloud routines, and various automation connectors.
Connection to the TanStack Supply Chain Attack
According to the company, the breach was likely a direct consequence of the May 2026 TanStack supply chain attack. During that security event, a group known as TeamPCP published 84 malicious artifacts across 42 TanStack packages. Because CrowdSec utilized a version of a TanStack package during that timeframe, the company suspects that the malware present in the compromised package led to the theft of an API key, granting attackers unauthorized access to the firm's private codebase.
Organizational Impact and Mitigation
CrowdSec has emphasized that the impact of this incident is strictly limited to the organization’s internal development assets. Investigations conducted by the company’s security team have so far uncovered no evidence of customer data exposure or leaked user credentials. Following the discovery of the breach last week, the company immediately initiated a security protocol to rotate all tokens and credentials that were potentially exposed during the May incident.
Risk Assessment of Exfiltrated Code
While the loss of proprietary source code is a serious concern, CrowdSec maintains that the stolen data does not pose an immediate threat to the wider user base or the security of their network. The firm stated that the stolen code cannot be used to replicate its infrastructure, as the logic is tied to internal data and proprietary tools that are not accessible to external actors. Furthermore, the company regularly audits its SaaS source code, and much of the code from May has since evolved significantly, reducing the utility of the stolen artifacts for malicious actors.
Broader Industry Context
This incident highlights the growing prevalence of supply chain compromises, a trend that has affected numerous organizations throughout the year. For further context on the landscape of recent security incidents, industry analysts have pointed to various high-profile events, such as the 23 Million User Records Compromised in Gyazo Data Breach and the widespread impact seen in the Brevo Supply Chain Attack Injects Malware Into 100,000 Websites. CrowdSec remains vigilant and continues to monitor its infrastructure for any sign of lateral movement or abnormal activity related to the breach.
Sources
- SecurityWeekCrowdSec Confirms Source Code Stolen in Supply Chain Attack