Skip to content
TECH CEO Daily

CrowdSec traces source code leak to ex-employee's laptop as software supply chain attacks target developers

A poisoned npm package, a departed employee's live GitHub token and a hijacked PHP library show attackers now target the people and tools that build software.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1CrowdSec says a former employee's laptop, infected via the TanStack npm compromise, let attackers copy about 170 private repositories.
  • 2Socket found North Korea-linked PolinRider code in development versions of a Packagist package with 700,000+ downloads.
  • 3CISA also flagged exploited flaws in GitLab and JFrog Artifactory, core tools in software delivery pipelines.

The news

Recent disclosures show software supply chain attacks reaching developers' own laptops, accounts and tools. Security firm CrowdSec said on September 17 that its source code had leaked, very likely through the compromised TanStack open-source package, and on September 18 that a former employee's laptop had been compromised and his still-valid GitHub token used to copy the code.

In the September 18 technical analysis, CrowdSec chief executive Philippe Humeau wrote that a threat actor called TeamPCP compromised the TanStack npm packages on May 11, 2026. npm is the main registry for JavaScript code libraries. According to Humeau, the former employee, who had kept GitHub organization access for transition work, was compromised in that attack. On May 22 his GitHub OAuth token was used to download about 170 private repositories in nine minutes from a Toronto IP address.

CrowdSec's September 17 statement said no client data was leaked and that its search for credentials enabling lateral movement had found none so far. The leak exposed source code and an API key used by a CI/CD (continuous integration and delivery) component, and the September 18 analysis acknowledged it also included 83 user email addresses used by CrowdSec's data science team and the names and emails of 51 potential investors from 2020. The Hacker News reported the code surfaced on an online forum on September 16, that CrowdSec rotated credentials on September 16 and 17, and that the company said its infrastructure and databases were not accessed. Humeau listed the gaps: no endpoint detection on developer machines, limited GitHub activity logging outside enterprise plans, and an OAuth token that left no audit trail.

A second case shows attackers working through developer accounts. Socket reported on September 17 that the North Korea-linked PolinRider campaign used a compromised GitHub developer account to inject malicious code, since mid-June, into four development branches of visanduma/nova-two-factor, a PHP package on the Packagist registry with more than 700,000 downloads. The code hid in configuration files and font files and ran automatically during builds or when a project folder was opened in an editor.

The tools that store and ship code are also under attack. CISA added an exploited GitLab path traversal flaw and two JFrog Artifactory authentication and authorization flaws to its catalog on September 11, after another Artifactory flaw on September 2. Google's Threat Intelligence Group said on September 8 that TeamPCP, which it tracks as UNC6780, has hit PyPI, npm and Docker Hub since March and stolen tokens from GitHub Actions runners to publish signed malicious packages.

The numbers

CrowdSec private repositories copied
About 170
Time to copy them
Nine minutes (05:52–06:01 UTC, May 22)
Gap between theft and public leak
May 22 to Sept 16
Downloads of the backdoored Packagist package
700,000+

Why CEOs should care

For CISOs, treat developer workstations and tokens as production assets. Put endpoint detection on engineering laptops, including tools that flag malicious packages and editor extensions. Require short-lived, scoped tokens for GitHub and package registries, and make offboarding revoke every OAuth grant, personal access token and SSH key the same day, including for staff kept on for transition work. Turn on audit logging for code hosting, which in CrowdSec's case was limited by its plan.

For engineering leaders, lock down how code runs automatically. Socket and the recent joint advisory on North Korea's WaterPlum both describe malware that executes when a developer opens a project folder. Enforce branch protection, alert on force-pushes that rewrite history, pin dependencies to reviewed versions, and avoid pulling development branches of third-party packages into builds.

For boards and CFOs, source code theft may never reach a regulatory filing, but it can expose API keys, user email addresses and investor lists, as CrowdSec's did. Ask whether developer tooling appears in the company's risk register, who owns it, and whether the security budget covers engineering endpoints at the same standard as finance systems.

The bigger picture

The pattern recurs across these cases: attackers compromise a popular open-source package or a developer account, harvest tokens from the machines that install it, and use those tokens weeks later where logging is weakest. The nearly four-month gap between CrowdSec's theft and its public leak shows how long a theft can go unnoticed. Defenders who focus only on production servers miss the systems where the keys to those servers are created.

What’s next

Expect more companies to trace incidents back to the May TanStack compromise as stolen tokens are used or sold. Watch for GitHub, npm and Packagist to tighten token lifetimes and publishing controls, and for customers to ask software vendors for evidence of developer-endpoint security in due diligence.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

CrowdSecSoftware supply chainGitHubNorth Korea

Earlier coverage of GitHub

All GitHub coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.