CrowdSec discloses a May 2026 private-repo leak via a backdoored TanStack component, found four months later
CrowdSec published a statement on 2026-09-17 saying it discovered on 2026-09-16 that a TanStack component it depends on had been backdoored to exfiltrate an API key with read access to its private codebase, exposing the SaaS console source, some AWS cloud routines, connectors and automations. The compromise window was a short period in May 2026, meaning the gap between exploitation and discovery was roughly four months. CrowdSec says no client data, credentials, passwords or PII were involved, has rotated all tokens and credentials, and argues the code's practical value has decayed since it only works within their ecosystem. Read alongside the Rust warning the same day, this is the second front-page supply chain story of the week where the initial vector was a trusted upstream dependency rather than the target.
Source
↳ Follow the thread