- Sources: primary, discussion
- Summary: The statement says a component used inside the organisation in May 2026 appears to have been backdoored to extract an API key carrying read access to its private codebase, and CrowdSec calls that vector very likely rather than established. CrowdSec states that no client data, login or password, name, organisation or other personally identifiable information was leaked, that it stores no personally identifiable information and no client logs, that the leak was only exploitable during a short timeframe in May 2026, and that all required tokens and credentials were rotated immediately. The statement attributes the same vector to the Mistral AI case, which makes two named companies losing private source to one dependency. No primary account of the TanStack incident itself was reachable on this run, so the vector is reported here as CrowdSec's attribution rather than as an independently sourced fact.
- Why it matters: A backdoored build-time component that extracts a CI token turns one dependency into read access across an organisation's private repositories, which CrowdSec bounds here to source code within a short May 2026 window with credentials since rotated, and it states the same vector reached a second named company.
- Follow-up: Track a primary account of the TanStack compromise, the affected component and version range, and any further named organisations.
send feedback on this story