# CrowdSec Addresses Supply Chain Attack

A supply chain attack by the TeamPCP threat group compromised approximately 170 private GitHub repositories of French cybersecurity firm CrowdSec, resulting in the theft of source code and limited exposure of user and investor information. The breach was facilitated by a former employee's OAuth token that was not revoked promptly, exposing critical gaps in endpoint detection and offboarding security practices. In response, CrowdSec has implemented endpoint detection and response (EDR) solutions and emphasized rapid access revocation to mitigate similar risks in the future.

- Procurement professionals should note the heightened risks associated with supply chain vulnerabilities, especially involving third-party code repositories and developer access controls.
- Agencies and contractors must prioritize robust offboarding procedures and endpoint security to prevent unauthorized access through stale credentials.
- This incident underscores the importance of integrating EDR tools and continuous monitoring in cybersecurity contracts and vendor assessments.
- Organizations involved in software development and cybersecurity procurement may find increased demand for solutions that enhance credential management and supply chain security.

**Jurisdictions:** international
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** September 24, 2026

### Vendors
- CrowdSec (victim company)

### Key Quotes
> Our infrastructure is AWS serverless, and we make heavy use of SSM/Secrets Manager, so the number of credentials present is very low but still warrants analysis.
> — Philippe Humeau, CEO

### Sources
- [TeamPCP Supply Chain Attack Leads to CrowdSec Source Code Being Stolen - DevOps.com](https://devops.com/teampcp-supply-chain-attack-leads-to-crowdsec-source-code-being-stolen) - DevOps.com