CrowdSec: May 2026 private GitHub source exposure; TanStack npm supply chain likely vector
CrowdSec statement (17 September 2026; informed 16 Sep) confirms a May 2026 leak of its private GitHub repositories (SaaS console, AWS cloud routines, connectors, automations). Public Security Engine repos are out of scope by design. CrowdSec says reports of ~300 repositories are accurate when 130+ intentionally public repos are included, and that the figure reflects code subdivision rather than 300 separate sensitive systems. Company assessment: TanStack npm supply-chain compromise (CVE-2026-45321; TanStack postmortem 11 May 2026 — 84 malicious versions across 42 @tanstack/* packages) is the very likely vector, similar to Mistral AI’s related case; a backdoored component appears to have extracted a CI/CD API key with read access to the private codebase during a short May window. CrowdSec says no client data, login/password, name, organisation, or PII/client logs were leaked; hunting for lateral-movement credentials found none so far; tokens/credentials rotated after confirmation. Thanks Fuites Infos for disclosure. Wire: The Hacker News 19 Sep summarises later CrowdSec reporting (~170 private repos copied 22 May via a former-employee GitHub OAuth token; 83 user emails / investor details in archive) — treat those extras as wire until mirrored on CrowdSec’s primary statement. Primary: CrowdSec; TanStack postmortem for CVE-2026-45321.
- Product
- CrowdSec private GitHub (SaaS console / AWS routines / connectors); TanStack npm (@tanstack/* Router/Start monorepo packages)
- Versions
- n/a for CrowdSec code leak; TanStack: 84 malicious versions of 42 packages published ~11 May 2026 (deprecated/removed — see TanStack postmortem)
- Exploited in Australia?
- unknown
- Patch to
- If you installed @tanstack/* packages on 2026-05-11: rotate GitHub/npm/SSH/cloud credentials from that host; review org GitHub OAuth tokens and ex-employee access; CrowdSec users: no action required per CrowdSec statement (monitor vendor updates).
Primary: CrowdSec — Source Code Exposure in May 2026 (17 Sep 2026) · Vendor: TanStack — npm supply-chain compromise postmortem (CVE-2026-45321, 11 May 2026) · CVE: CVE-2026-45321 · The Hacker News — CrowdSec / TanStack / ~170 private repos wire (19 Sep 2026)
