$ techbeacon▋
Phishing

Former Employee’s Account Used in Supply‑Chain Breach, CrowdSec Reveals Massive GitHub Data Theft

Former Employee’s Account Used in Supply‑Chain Breach, CrowdSec Reveals Massive GitHub Data Theft

French cybersecurity firm CrowdSec disclosed on September 18 that an attacker exfiltrated roughly 170 of its private GitHub repositories on May 22, exploiting the credentials of a recently departed employee.

According to the company, the former staff member’s GitHub access had not been revoked after his exit, allowing the intruder to log in with a valid account. The attacker then used that foothold to clone the private codebases to an external location, a breach that could expose proprietary detection rules, integrations, and internal tooling.

CrowdSec linked the incident to a broader supply‑chain compromise involving the popular TanStack npm package. Earlier in the year, security researchers reported that the TanStack library had been hijacked, injecting malicious code that could harvest credentials from developers' machines. CrowdSec believes the same malicious payload reached the former employee’s laptop, providing the means to capture his stored GitHub token.

The breach underscores a recurring challenge in the industry: the timely revocation of access rights when personnel leave an organization. While many firms automate off‑boarding procedures, CrowdSec admitted that its manual process left the account active for weeks after the employee’s departure. This lapse, combined with a compromised endpoint, created a perfect storm for data theft.

Beyond the immediate loss of source code, the incident raises concerns about downstream users of CrowdSec’s open‑source components. If the stolen repositories contained unpublished security rules or configuration defaults, threat actors could potentially weaponize them against other organizations that rely on CrowdSec’s platform.

In response, CrowdSec said it has reset all credentials associated with the former employee, conducted a comprehensive audit of its GitHub organization, and is tightening its off‑boarding workflow. The company also plans to enhance endpoint security for remote workers, including mandatory device encryption and regular malware scans.

Security analysts note that the attack illustrates how supply‑chain vulnerabilities in third‑party libraries can cascade into unrelated services. “A compromised npm package can become a conduit for credential theft, especially when organizations lack strict account management,” said a researcher at a European cyber‑defence institute.

While no public evidence has emerged that the stolen code has been weaponized, CrowdSec is monitoring for any signs of misuse. The firm has notified affected stakeholders and is cooperating with law enforcement to trace the perpetrators. The episode serves as a reminder that robust identity management and rapid response to supply‑chain threats are essential components of modern cyber hygiene.

Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related