CrowdSec disclosed that a backdoored TanStack dependency was used in May to extract an API key with read access to its private repositories, resulting in the unauthorized copying of source code from roughly 300 repositories. The exposed material included code for its SaaS console, AWS Cloud routines, connectors, and automations; more than 130 affected repositories containing the open-source CrowdSec Security Engine were already public.
The company was notified of the incident on September 16 and said it found no evidence that customer data, customer logs, or credentials enabling lateral movement were compromised. CrowdSec rotated affected API tokens and other credentials, increased monitoring, and began reviewing its code and systems for potential backdoors linked to the supply-chain compromise.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
On September 17, 2026, CrowdSec publicly disclosed the incident, saying exposed private code included SaaS console, AWS Cloud, connector, and automation code. It stated that no customer data or logs were compromised, rotated affected tokens and credentials, and increased monitoring and backdoor investigations.
CrowdSec was notified of the source-code exposure on September 16, 2026, and its internal teams confirmed the incident.
In May 2026, a backdoored TanStack dependency extracted an API key with read access to CrowdSec private repositories. Unauthorized actors copied source code from roughly 300 repositories during a short exploitation window.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.