CrowdSec 源代码泄露
CrowdSec Source Code Leak

原始链接: https://www.crowdsec.net/blog/crowdsec-statement-source-code-exposure

9月16日,CrowdSec 证实其私有 GitHub 存储库发生源代码泄露,此次泄露可能源于 2026 年 5 月 Tanstack 组件的供应链攻击。受影响的主要是包含 SaaS 控制台代码、AWS 例程和自动化工具的私有存储库,其公共开源存储库未受影响。 CrowdSec 强调,由于公司不存储客户数据、个人身份信息(PII)或内部日志,因此未造成此类信息的泄露。尽管被泄露的代码具有一定价值,但 CrowdSec 指出,这些代码与其基础设施高度关联,限制了其被外部滥用的可能性。此外,过去四个月内其代码库已发生显著演变。 发现问题后,团队已轮换所有相关令牌和凭据,并进行了深入调查,目前未发现横向移动的迹象。此次泄露仅限于 5 月的短时间内,公司正在监测异常活动。CrowdSec 将继续调查,并坚称此次安全漏洞不会对用户或平台的安全核心运营构成直接威胁。

Hacker News 最新 | 往期 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 CrowdSec 源代码泄露 ( crowdsec.net ) 15 分 | 由 eccgecko 发布 | 56 分钟前 | 隐藏 | 往期 | 收藏 | 1 条评论 sandeepkd | 4 分钟前 [–] 有趣的是,读了他们的网站标语,他们声称知道是谁在攻击你,但偏偏没发现是谁攻击了他们自己。 事实证明,他们并非真正的安全公司,只是一个恶意 IP 聚合器。理想情况下,这类聚合器问题最适合由受信任的非营利组织来处理,因为提供数据需要一定的可信度,且查询数据需收取象征性费用以维持运营。 回复 准则 | 常见问题 | 列表 | API | 安全 | 法律 | 申请 YC | 联系 搜索:
相关文章

原文

On September 16, CrowdSec was informed of a source code leak involving our GitHub repository, which occurred in May 2026. Our team verified and confirmed the report. CrowdSec source code consists of two parts: a private one and another that hosts our Free Open Source Software (i.e., the Security Engine), which is public by design and therefore out of scope. The private part, though, contains the source code for our SaaS console, some AWS Cloud routines, some connectors, and automations. 

The news headline claiming 300 different repositories is accurate (when you include the 130+ public ones), though that number mostly reflects the code’s subdivision rather than a specific volume. We do not confirm any “other file contained” or “internal development material”, since all the code is published in these repositories. The API related information is the token used by the CI/CD component itself. (see below)

No client data, login/password, name, organization, or anything else was leaked, and CrowdSec doesn’t store PII or client logs; the impact is limited to CrowdSec. Our team quickly hunted for any token, credential, or sensitive leak that could enable lateral movement but found none so far.

The code contained in these private repositories has value but cannot really harm CrowdSec, since our efficiency depends on our network effect and size, which code alone can’t replicate. We regularly audited the SaaS source code, and its leakage shouldn’t pose an immediate threat either. Most of the leaked code has evolved significantly over those four months, but we will closely monitor for any abnormal activity. Also, using it outside of CrowdSec seems unlikely because it only interacts with our data and tools and cannot really be leveraged in another context. 

We will keep you updated as we continue investigating, but the Tanstack compromise is very likely to have been the leak vector (more about it here), as in the case of the Mistral AI case. This component was used in our organization in May and appears to have been backdoored to extract an API key with authorization to read the private codebase. The leak was only exploitable during a short timeframe in May 2026.

We nevertheless immediately rotated all required tokens & credentials to prevent further incidents.

The team would like to thank Fuites Infos for their timely, professional outreach in reporting the issue.

联系我们 contact @ memedata.com