{
  "id": 9510835,
  "title": "TeamPCP Supply Chain Attack Leads to CrowdSec Source Code Being Stolen",
  "url": "https://urgent.news/2026/09/24/teampcp-supply-chain-attack-leads-to-crowdsec-source-code-being-stolen",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-24T07:16:00.000Z",
  "source": {
    "name": "DevOps.com",
    "slug": "devops-com",
    "url": "https://devops.com/teampcp-supply-chain-attack-leads-to-crowdsec-source-code-being-stolen/"
  },
  "original_language": "en",
  "account": "A French cybersecurity firm called CrowdSec experienced a supply chain attack on May 22, resulting in the theft of source code from 170 of its private GitHub repositories. The attack was carried out by the TeamPCP threat group, who had previously targeted the npm package manager. TeamPCP utilized a self-propagating worm to obtain credentials and tokens, publishing 84 malicious artifacts across 42 TanStack packages. The stolen source code remained undetected until September 16, when it was leaked on a dark web cybercrime marketplace. CrowdSec, which collaborates with other organizations to share threat intelligence, had not yet realized the extent of the breach. The stolen information included an Amazon Web Services (AWS) Simple Notification Service token, email addresses of 83 users, and the first and last names of 51 potential investors dating back to 2020. CrowdSec had implemented several security measures, such as privilege separation, two-factor authentication, audits, logs, and automated code analysis, but failed to employ endpoint detection and response (EDR) on developers' systems and did not promptly revoke access to the former employee's laptop upon his departure from the company.",
  "summary": "CrowdSec says attackers stole source code from about 170 private GitHub repositories after a TanStack npm supply chain attack exposed an OAuth token tied to a former employee.",
  "key_points": [
    "French cybersecurity firm CrowdSec suffered supply chain attack on May 22",
    "TeamPCP threat group stole source code from 170 private GitHub repos",
    "Stolen data included AWS token, user emails, investor details"
  ],
  "editors_take": "The breach highlights vulnerabilities in CrowdSec's security measures, particularly the lack of endpoint detection and response on developer systems and delayed access revocation, which can be exploited by threat groups.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}