Threat Intelligence

Former Employee's Compromised Laptop Led to Leak of 170 CrowdSec Repositories

The Hacker News · 19 Sept 2026
Key Takeaway Revoke all account and system access for departing employees immediately, rather than leaving accounts open for convenience, as this can become a hidden entry point for attackers.

French security company CrowdSec has revealed that an attacker copied around 170 of its private GitHub repositories on 22 May, using the account of an employee who had recently left the company. The account still had GitHub access because the company had kept it open so he could finish outstanding work. CrowdSec says the employee's laptop had been compromised as part of the earlier supply chain attack on TanStack's npm packages, tracked as CVE-2026-45321, in which malicious code stole credentials such as GitHub tokens, SSH keys and cloud credentials from developer machines.

The stolen code surfaced on an online forum on 16 September, along with the email addresses of 83 CrowdSec users and personal details of 51 potential investors from 2020. CrowdSec says the attacker only copied code and did not access its infrastructure, databases, or make any changes. The company removed the former employee's account from its GitHub organisation on 25 May, three days after the copy occurred, though it did not learn of the leak itself until months later. It says the token used left no trace in available logs and had already expired by the time it investigated, though GitHub support later confirmed TanStack as the source.

CrowdSec is not the only company affected by the TanStack npm compromise. Mistral AI and OpenAI have both reported that employee devices were affected by the same attack, with OpenAI confirming unauthorised access to some internal code repositories.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.