CrowdSec's final report connects a May package compromise to a former employee's still-valid GitHub access, a nine-minute copy of about 170 private repositories and a disclosure delayed until the archive appeared on a criminal forum.
What changed
Treat CrowdSec's disclosure as an identity and software-supply-chain incident, not merely a code leak. Validate developer offboarding, OAuth-token governance, repository-clone visibility and secret exposure together. On May 11, 2026, CrowdSec says 42 TanStack packages were backdoored with the credential-harvesting malware Shai Hulud.
Public record through 2026-09-21. Source references count citations across published briefings, including repeated sources. Explore the record and its limits →
What We Publish / What We Sell
D
Free · Public
The Daily
Five evidence-backed selections for security leaders, every weekday.
Scores are Security.io editorial assessments, not external metrics. They weight blast radius, privileged placement, control urgency, confirmed impact and operational consequence across the selected edition. Exposure: 82. Urgency: 90. Business consequence: 87. Focus the chart and use the up and down arrow keys for detail. Source: Security.io editorial score, 0–100, derived from the five selected stories and their validated sources.