Start with Identity
News

CrowdSec kept a departing engineer's GitHub access open, and lost 170 private repositories through it

An engineer's laptop was infected in the May TanStack npm attack. Eleven days later his still-active GitHub OAuth token was used to copy about 170 of CrowdSec's private repositories. The company had left his access open so he could finish some work.

By SWI Community TeamSep 19, 2026

CrowdSec disclosed on September 18 that an attacker copied about 170 of its private GitHub repositories on May 22 using the account of an employee who had just left. His laptop had been infected on May 11 by the malicious TanStack npm releases (CVE-2026-45321), which stole GitHub tokens, SSH keys and cloud credentials from the machine. CrowdSec had kept his GitHub access open so he could finish some work, and did not revoke it until May 25, three days after the copying. The repositories held source for its web console, data science scripts and models, automation scripts, and the consensus logic that decides which IP addresses join its blocklist. They also exposed 83 user email addresses and the names, emails and investment details of 51 prospective investors from 2020. The code surfaced on a forum on September 16; CrowdSec rotated the exposed credentials on September 16 and 17.

Why it matters

This is the leaver process failing in its most ordinary form. Nobody forgot the account; someone decided to keep it open, informally and with no end date, because there was work to finish. That decision has to exist as a time-boxed grant with an owner and an expiry, scoped to the repositories the work needs, not as a full account left running. The same applies to contractors and to people moving teams. See orphaned account abuse and mover entitlement accumulation.

The second failure is the rotation date. The token was stolen in May and the secrets in those repositories were rotated in September, after the code appeared publicly. A known infection on a developer machine is the trigger for rotating everything that machine could reach, not a public leak four months later. If your incident process waits for evidence of use before rotating, this is what that wait costs. See secrets in repositories and CI.

Source: The Hacker News

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.