‼️ This week cybersecurity company CrowdSec learned that attackers had read its private GitHub repositories back in May.
The likely way in was TanStack, a widely used set of JavaScript libraries CrowdSec's developers were working with at the time.
Dozens of poisoned packages went out, carrying malware that stripped tokens and credentials off developer machines.
In CrowdSec's case it lifted an API key that could read the private codebase.
The tip came from outside the company, from French leak-monitoring outfit Fuites Infos.
CrowdSec says no customer data, credentials or logs were taken, and that the stolen code — the SaaS console, some AWS routines, connectors — is of limited use to anyone else because it only talks to CrowdSec's own systems.
The open source Security Engine was public by design.
All tokens have been rotated.
https://www.crowdsec.net/blog/crowdsec-statement-source-code-exposure
Post #1575
1.18K


- 😱 5
- 😁 4
- 💩 2