CrowdSec Lost 170 Private Repos After Hackers Reused a Token From the TanStack npm Attack
CrowdSec says attackers copied about 170 private GitHub repositories on 22 May 2026 using a former employee's OAuth token stolen in the TanStack npm attack. The leaked dump also exposed 83 user emails and 51 investors.

CrowdSec, the French open-source security firm, says attackers copied around 170 of its private GitHub repositories in May, and that the break-in traces back to the same poisoned npm packages that rattled the TanStack ecosystem earlier this year.
The copy happened on 22 May. In its September 18 report, the company says the intruder logged in through the GitHub account of an employee who had recently left but whose access CrowdSec had deliberately kept open so he could wrap up some work. His laptop had been compromised in May's TanStack supply-chain attack, in which 84 malicious versions of 42 npm packages (tracked as CVE-2026-45321) harvested GitHub tokens, SSH keys, and cloud credentials from developer machines.
Eleven days after those packages went live, a stolen OAuth token from that account was used to clone the repositories. CrowdSec pulled the account from its organization on 25 May, three days after the copy and months before the code surfaced. The dump appeared on an online forum on 16 September.
What leaked was not just code. Alongside the web console, data science models, and the consensus algorithm that decides which IP addresses land on CrowdSec's blocklists, the archive held the email addresses of 83 users and the names, emails, and investment details of 51 potential investors from 2020. CEO Philippe Humeau apologized to those investors directly in the report.
CrowdSec insists the damage stops there. The account was used only to copy code, it says; infrastructure and databases were untouched, and nothing was altered. The one usable secret in the dump was an AWS SNS credential limited to a single notification topic, and someone tried it on 17 August, a month before the leak went public, without getting further.
CrowdSec's story shifted along the way. Its first statement, a day before the fuller report, said "No client data, login/password, name, organization, or anything else was leaked" and blamed a backdoored TanStack component running inside CrowdSec itself. The September 18 report drops that: it found none of the malicious TanStack versions in its own code, pins the breach on the former employee's token, and lists the very investor and user details the earlier note said were safe. Some later writeups, including SecurityWeek, still carry the original framing and a higher figure of roughly 300 repositories.
The same TanStack wave reached bigger names. Mistral AI said one developer device was caught up in it, and OpenAI said two employee machines were affected, with unauthorized access to a limited set of internal code repositories. It fits a run of trouble Dupple has tracked across npm supply-chain compromises and stolen OAuth tokens this year.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free