{"id":5137,"date":"2026-09-24T07:55:55","date_gmt":"2026-09-24T07:55:55","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/09\/24\/teampcp-supply-chain-attack-leads-to-crowdsec-source-code-being-stolen\/"},"modified":"2026-09-24T07:55:55","modified_gmt":"2026-09-24T07:55:55","slug":"teampcp-supply-chain-attack-leads-to-crowdsec-source-code-being-stolen","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/09\/24\/teampcp-supply-chain-attack-leads-to-crowdsec-source-code-being-stolen\/","title":{"rendered":"TeamPCP Supply Chain Attack Leads to CrowdSec Source Code Being Stolen"},"content":{"rendered":"<div><img data-opt-id=1556438459  fetchpriority=\"high\" decoding=\"async\" width=\"770\" height=\"330\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/09\/crowdsec_github_breach_770x330.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=693607498  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/09\/crowdsec_github_breach_770x330-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p>About 170 private GitHub repositories belonging to French cybersecurity company CrowdSec were compromised and source code was stolen by attackers earlier this year in the wake of an npm supply chain attack in May by the notorious <a href=\"https:\/\/securityboulevard.com\/2026\/08\/arrests-hinder-teampcp-but-the-threat-is-still-out-there-researchers-say\/\" target=\"_blank\" rel=\"noopener\">TeamPCP threat group<\/a> on TanStack.<\/p>\n<p>TeamPCP used the <a href=\"https:\/\/devops.com\/widespread-mini-shai-hulud-campaign-is-a-matter-of-trust\/\" target=\"_blank\" rel=\"noopener\">Mini Shai-Hulud self-propagating worm<\/a> to grab credentials and tokens and published 84 malicious artifacts across 42 TanStack packages, and CrowdSec GitHub repositories were caught up in the attack.<\/p>\n<p>CrowdSec, which crowdsources threat intelligence, earlier this month learned that source code had been stolen from the laptop of a former employee that was compromised in the TanStack attack. An OAuth token taken from the ex-employee\u2019s GitHub account still had permission to read the vendor\u2019s private inventories.<\/p>\n<p>TeamPCP on May 22 took credit for the supply-chain attack on TanStack 11 days earlier. In all, about 300 CrowdSec public and private repositories were compromised. Also on May 22, one of the founders of the BreachForum hacking site and another member downloaded the contents of the private CrowdSec GitHub repositories from an IP address in Toronto, Canada, a process that took about nine minutes.<\/p>\n<h3>Revocation Was Too Late<\/h3>\n<p>Three days later, the company revoked GitHub access to the former employee\u2019s laptop, but by that time the damage was done. However, the theft of the source code was undetected until September 16, when it was leaked on pwnforum, a dark web cybercrime marketplace.<\/p>\n<p>The damage wasn\u2019t widespread, with CrowdSec researchers <a href=\"https:\/\/www.crowdsec.net\/blog\/crowdsec-statement-source-code-exposure\" target=\"_blank\" rel=\"noopener\">writing<\/a> that \u201cno client data, login\/password, name, organization, or anything else was leaked, and CrowdSec doesn\u2019t store PII or client logs; the impact is limited to CrowdSec.\u201d<\/p>\n<p>However, as CrowdSec CEO Philippe Humeau <a href=\"https:\/\/www.crowdsec.net\/blog\/tanstack-supply-chain-attack-analysis\" target=\"_blank\" rel=\"noopener\">wrote in a blog post<\/a>, \u201cwe were very close to clean.\u201d Among the leaked information was a token for using Amazon Web Services\u2019 (AWS) Simple Notification Service.<\/p>\n<p>\u201cOur infrastructure is AWS serverless, and we make heavy use of SSM\/Secrets Manager, so the number of credentials present is very low but still warrants analysis,\u201d Humeau wrote. \u201cMost of the tokens and secrets present in the source code had been revoked or rotated before the leak, but we can see that the ones present and usable have been probed.\u201d<\/p>\n<h3>Information Leaked<\/h3>\n<p>In addition, a small amount of client and partner information was leaked, including some email addresses \u2013 mostly Gmail \u2013 of 83 users, or less than 1% of the company\u2019s 150,000 users. Also disclosed were the first and last names of 51 potential investors dating back to 2020, along with their email addresses and their investment context.<\/p>\n<p>CrowdSec researchers initially had trouble tracking the stolen OAuth token to the source, but with help from GitHub support staff, they were able to determine it was taken from the laptop of the former employee \u201cwho had just left the company, but that was still part of the GitHub organization for legitimate reasons, and his account was used to dump the repositories,\u201d the CEO wrote.<\/p>\n<p>He detailed the range of security features CrowdSec has in place, including privilege separation, two-factor authentication, audits, logs, penetration testing, automated code analysis, and age monitoring for npm nodes.<\/p>\n<h3>No EDR or Access Cutoff<\/h3>\n<p>However, there were a couple of security issues. One was not having endpoint detection and response (EDR) on developers\u2019 systems, though that\u2019s changed, according to Humeau. He wrote that the company is using it to focus on such threats as malicious packages and extensions.<\/p>\n<p>\u201cAs supply chain attacks become the new plague and virtually anyone can get caught in them, we should have done this earlier,\u201d he wrote.<\/p>\n<p>The other was not immediately cutting off access to the former employee\u2019s laptop after he left the company. In a study by job search platform Zippia, 76% of IT leaders surveyed strongly agreed that <a href=\"https:\/\/www.zippia.com\/employer\/offboarding-statistics\/#:~:text=According%20to%20our%20extensive%20research,have%20a%20fully%20automated%20process.\" target=\"_blank\" rel=\"noopener\">offboarding represents a significant security threat<\/a>, with 20% of companies saying they had experienced a data breach connected to a former employee.<\/p>\n<p>\u201cPrompt access revocation is important during the offboarding process to protect company data, prevent security breaches, and maintain compliance with legal and regulatory standards,\u201d officials with identity management vendor Lumos <a href=\"https:\/\/www.lumos.com\/topic\/employee-offboarding-automation-removing-access-for-terminated-employees-why-is-it-important-to-immediately-deactivate-employee-accounts-and-access-immediately-after-termination\" target=\"_blank\" rel=\"noopener\">wrote<\/a>. \u201cWhen an employee leaves, failing to revoke their access rights can quickly lead to unauthorized access, data breaches, and the potential misuse of sensitive information.\u201d<\/p>\n<p><a href=\"https:\/\/devops.com\/teampcp-supply-chain-attack-leads-to-crowdsec-source-code-being-stolen\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>About 170 private GitHub repositories belonging to French cybersecurity company CrowdSec were compromised and source code was stolen by attackers [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5138,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-5137","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5137","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=5137"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5137\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/5138"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=5137"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=5137"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=5137"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}