TGViewer
International Cyber Digest International Cyber Digest @intcyberdigest · 7.77K subscribers
Post #1575 1.18K
‼️ This week cybersecurity company CrowdSec learned that attackers had read its private GitHub repositories back in May.

The likely way in was TanStack, a widely used set of JavaScript libraries CrowdSec's developers were working with at the time.

Dozens of poisoned packages went out, carrying malware that stripped tokens and credentials off developer machines.

In CrowdSec's case it lifted an API key that could read the private codebase.

The tip came from outside the company, from French leak-monitoring outfit Fuites Infos.

CrowdSec says no customer data, credentials or logs were taken, and that the stolen code — the SaaS console, some AWS routines, connectors — is of limited use to anyone else because it only talks to CrowdSec's own systems.

The open source Security Engine was public by design.

All tokens have been rotated.

https://www.crowdsec.net/blog/crowdsec-statement-source-code-exposure
  • 😱 5
  • 😁 4
  • 💩 2
More from @intcyberdigest
  1. Sep 20, 2026Owning a drone in Beijing will be illegal from 15 November. The revised city rules ban pos…
  2. Sep 20, 2026‼️ BREAKING: Jensen Huang says Dario Amodei and Sam Altman are lying by asking for more la…
  3. Sep 20, 2026UnitedHealth used an AI model it knew had a 90% error rate to cut off care for elderly pat…
  4. Sep 20, 2026Claude Code was told to clear a temp folder. In 103 seconds it decided to delete about 48,…
  5. Sep 20, 2026‼️ Rust’s best-known maintainers are under attack. Attackers lure victims into installing…
  6. Sep 20, 2026The US health department wants Americans to write in about health problems they believe we…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →