The record
Written from the 1 report below. Nothing here is unsourced.
- An attacker compromised a former employee's laptop via a supply chain attack involving malicious TanStack npm packages.
- Using stolen GitHub tokens, the attacker accessed and copied 170 of CrowdSec's private repositories.
- The stolen data included company source code, email addresses of 83 users, and contact details for 51 potential investors from 2020.
- CrowdSec confirmed that its internal infrastructure and databases remained secure and that it has since rotated the exposed credentials.
What to watch next
- Future notifications to the 83 affected users and 51 investors.
- Potential regulatory reporting outcomes regarding the leaked investor data.
- Ongoing impact of the TanStack supply chain attack on other affected organizations.
Who said what1
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Philippe Humeau
CEO
1 quote · 1 outlet
“for this I personally apologize.”
In the article
…came from a 2020 system that CrowdSec says was never meant to be public. The company says it will report the leak to the investors and to the authorities. CEO Philippe Humeau wrote to the investors in the report that " for this I personally apologize. " The affected company rotated the exposed credentials on September 16 and 17. It did not require endpoint protection software on developers' machines at the time, but it now runs such software on the laptops of staff…
Coverage1
All filed from India
Named France · AWS · CrowdSec · GitHub · Mistral AI · OpenAI · Philippe Humeau · TanStack
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
