Cybersecurity firm CrowdSec confirms hacker leaked 170 stolen private GitHub repositories
A hacker leaked private CrowdSec source code stolen in May 2026 through the TanStack npm supply-chain attack; the leak, exposing 83 user emails and 51 investor records, only surfaced publicly this September. Per The Hacker News / CrowdSec.
Cybersecurity company CrowdSec has confirmed that attackers copied around 170 of its private GitHub repositories in May 2026, after a former employee's machine was compromised through the TanStack npm supply-chain attack (42 backdoored packages). The stolen files, including source code, machine learning models, and an AWS token later tested by attackers, stayed hidden until the archive surfaced on a hacking forum on September 16, 2026. The leak exposed 83 user email addresses (about 0.05% of CrowdSec's roughly 150,000 users) and the names of 51 potential investors from 2020. CrowdSec says its infrastructure, databases and blocklist were not affected. Sources: The Hacker News, CrowdSec.