网络安全公司CrowdSec于9月16日公开确认其GitHub私有仓库在2026年5月遭遇源代码泄露1。此次事件涉及约300个不同的代码仓库被泄露,其中包括130多个公有仓库1。泄露内容涵盖SaaS控制台源代码、AWS例程、连接器以及自动化脚本等私有代码资产1。
CrowdSec经调查认为,泄露源头很可能是Tanstack组件被植入后门,该后门用于提取具有私有代码库读取权限的API密钥1。公司表示未发现客户数据或凭证泄露1。作为应对措施,CrowdSec已立即轮换所有必需的令牌和凭证1。
Cybersecurity company CrowdSec disclosed on September 16 that approximately 300 of its GitHub repositories, including more than 130 public ones, were compromised in a source code breach that occurred in May 2026 1. The leaked repositories contained proprietary code for the company's SaaS console, AWS Cloud procedures, connectors, and automation scripts 1.
The company traced the breach to a compromised Tanstack component that had been injected with a backdoor designed to extract API keys with read access to private code repositories 1. CrowdSec stated that the window of exposure was brief and occurred only during May 2026 1. In response, the company immediately rotated all necessary tokens and credentials 1.
CrowdSec emphasized that no customer data, login credentials, or organizational information was exposed in the incident 1. The company also confirmed that no tokens or credentials capable of enabling lateral movement were compromised, and that it does not store personally identifiable information or customer logs 1.
评论
还没有评论,欢迎留下第一条。