An attacker downloaded approximately 170 of CrowdSec's private GitHub repositories on May 22, using the account of an employee who had recently departed This article explores cloud credentials tanstack. . CrowdSec revealed that the individual's laptop was compromised during a May supply chain attack on TanStack, where malicious versions of TanStack's npm packages stole credentials from developers' machines.

Installing any of these versions triggered code that accessed credentials, including GitHub tokens, SSH keys, and cloud credentials, as per TanStack's advisory. The archive contained the company's web console, data science scripts, models, automation scripts, and the consensus algorithm that determines which IP addresses are added to the blocklists. An attacker would need to trigger detections from multiple trusted engines across various networks, at considerable expense.

The sole accessible credential from the leak pertains to AWS's SNS notification service, which can only publish messages to a single topic. CrowdSec reports approximately 150,000 active users. It did not require any endpoint protection software on the developers' machines at that time, but it now installs such software on the staff members' laptops who work with its code or systems.

The initial statement claimed "No client data, login/password, name, organization, or anything else was leaked," indicating minimal impact. It indicated that a component employed within CrowdSec in May was allegedly backdoored to obtain an API key, which could access the private code.