CrowdSec: Departed Employee’s Live GitHub Access → ~170 Private Repos Cloned

By George Bailey   Published: 09/20/26   Updated: 09/20/26   3 min read

The breach wasn’t a novel zero-day on CrowdSec’s product. It was an offboarding gap: a former employee’s GitHub org access stayed open, his laptop had been hit by the TanStack npm credential stealer, and on May 22 an attacker cloned about 170 private repositories.

What happened

CrowdSec disclosed in mid-September 2026 that private source (SaaS console, automations, data-science code, consensus logic) appeared online. Their September 18 analysis says the copy used a GitHub OAuth token from an employee who had just left, whose access CrowdSec had intentionally kept open so he could finish work. The laptop was compromised in the TanStack supply-chain attack (CVE-2026-45321, malicious npm packages published May 11 that stole GitHub tokens, SSH keys, and cloud credentials).

Timeline that matters for operators:

CrowdSec says infrastructure/databases were not accessed, code was not modified, and usable credentials in the archive were limited (one SNS publish attempt Aug 17 went nowhere). Thresholds for their consensus blocklist became public; they argue poisoning remains costly.

Why it matters

Two ordinary failures lined up: a supply-chain steal on a developer endpoint, and identity offboarding that stopped at the IdP while GitHub (and similar) stayed live. That pattern is not unique to CrowdSec — Mistral and OpenAI reported related TanStack exposure. If your offboarding checklist doesn’t include GitHub/GitLab org membership, personal PATs, OAuth apps, cloud console roles, package registries, and CI secrets, you are rehearsing this incident.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.