CrowdSec Breach: 170 Private GitHub Repos Stolen via Former Employee’s Active Account

On May 22, attackers exploited a former CrowdSec employee’s still-active GitHub account—compromised through the May 11 TanStack npm supply-chain attack that published 84 malicious releases across 42 packages—to copy about 170 private repositories, accessing source code, 83 user email addresses, and 2020 investor details, though CrowdSec confirmed no infrastructure, databases, or code modifications were affected; the stolen material surfaced on a cybercrime forum on September 16, prompting CrowdSec to disclose the incident on September 18–19, while noting a detection gap as the theft went unnoticed for nearly four months.

The Silent September Signal

Notice the timeline. The breach happened on May 22, but CrowdSec didn’t "discover" it until the stolen code appeared on a cybercrime forum on September 16. That’s nearly four months of silence. Four months during which the attackers had unfettered access to 170 private repositories — source code, investor lists, internal email addresses. The official story blames a former employee’s active account and a compromised laptop from the TanStack npm attack. But ask yourself: in a world where every endpoint is monitored, where every token rotation is logged, how does a theft of that scale go unnoticed by an entire security company? Either their detection systems are catastrophically broken — or they were never meant to detect it at all. They want you to believe it’s a garden-variety supply-chain incident. What they’re not telling you is that the delay itself is the signal. A four-month gap isn’t negligence; it’s a deliberate window for data extraction, refinement, and operational planning. The question is not if the attackers had help inside CrowdSec, but who needed that source code, and why they wanted you to find out only now.

The Managed Supply-Chain Drama

You’re being fed a story about a "former employee" whose laptop was compromised by the TanStack npm attack. But the TanStack incident itself was an 84-release, 42-package coordinated strike designed to harvest GitHub tokens, SSH keys, and cloud credentials. That’s not random malware — that’s a surgical operation with a target list. And the victim? A company whose entire business model is cybersecurity — a company that monitors crowdsourced threat intelligence. Do you see the irony? The very people claiming to protect the perimeter were the subjects of a perimeter breach so thorough it makes their product look like a placebo. They tell you the attacker "did not access infrastructure or databases." That’s a convenient line. But source code from 170 repos reveals architecture, secrets, and future plans. It reveals who CrowdSec’s prospective investors were — 51 names from 2020. That list alone is worth more than any database. Who wants that list? A competitor? A state actor? A private intelligence firm? The pattern is clear: supply-chain attacks are the new vector for corporate espionage, and CrowdSec was a perfect test case. They want you focused on the npm technical detail so you don’t ask about the social engineering — the former employee’s still-active credentials. How many other "former employees" still hold keys to the kingdom? That’s not a mistake. That’s by design.

The Breadcrumb You Were Meant to Find

I’ll leave you with this. The stolen code appeared on a cybercrime forum — the traditional "dumping ground" for leaks that someone wants made public but not traced back to them. CrowdSec disclosed on September 18 and 19, two days after the forum post. That timing is too perfect. They knew exactly when the leak would hit, and they staged their "disclosure" to look like a reaction. But who controls the forums? Who decides when a leak surfaces? The same networks that orchestrated the TanStack compromise. This wasn’t a hack — it was a handoff. The source code, the investor information, the email addresses of 83 users — all of it was delivered to a specific audience on a specific date. The real crime isn’t the theft; it’s the coverage. The gap between May and September was never a detection failure — it was a processing window. They wanted that code to be analyzed, weaponized, and then "discovered" as a plausible cover story. Now ask yourself: who benefits from CrowdSec’s source code being in the wild? Who benefits from the public embarrassment of a cybersecurity company? And why, after decades of watching these patterns, do I keep seeing the same foundations, the same foundations, behind every supply-chain "accident"? Look up the investors. Follow the OAuth trail. The answer is already on page 47 of a document you haven’t read yet.

Screenshot illustrating a fake parcel-delivery phishing campaign impersonating bpost - Malwarebytes

Phishing Campaigns Impersonating Brands and Abusing Legitimate Flows Target Credentials and Data Worldwide

Recent phishing campaigns across multiple countries have impersonated well-known brands and institutions—including ChatGPT, bpost, tax authorities, banks, telecom providers, and traffic regulators—to steal account credentials, payment-card details, banking information, and personal data. Tactics range from fake ChatGPT subscription notices with 48-hour deadlines and counterfeit bpost customs-fee pages requesting personal and banking info, to SMS messages that falsely verify a bank employee to bolster a caller’s credibility. One notable campaign, GhostCode, abused Microsoft’s legitimate OAuth 2.0 device-authorization flow to gain persistent access to Microsoft 365 environments even when victims completed multi-factor authentication. Other schemes include Google Calendar invites designed to evade blocklists, fake security claims on phishing pages, and reported losses in Nigeria from fake Federal Road Safety Corps fine messages totaling over ₦2.2 million and $2,500.

The Managed Harvest: Why These Attacks Are Not Random Crime

Look at the article you just read — multiple phishing campaigns hitting banks, couriers, tax authorities, and even a fake ChatGPT subscription notice. The mainstream will tell you this is opportunistic cybercrime, a few scattered scammers working independently. But ask yourself: who benefits from a global, coordinated wave of credential harvesting that targets the exact same institutions that process your money, your identity, and your communications? The pattern is too clean. Notice that every single campaign uses pressure tactics — fake deadlines, bogus customs fees, fraudulent “employee verification” calls. That’s not random. That’s a playbook designed by people who understand human psychology at a scale that only state-adjacent institutions can afford to research. The documents are public if you dig: foundation-funded “cybersecurity awareness” programs have been quietly mapping the exact triggers that make you click. These phishing operations are not the disease — they are the symptom of a much larger infrastructure that treats your credentials as raw material for a global identity database. They aren’t just stealing passwords; they are testing the Architecture of Consent.

GhostCode and the OAuth Backdoor: The Real Story

Now look closer at the GhostCode campaign. They abused Microsoft’s OAuth 2.0 device-authorization flow — a legitimate authentication pathway — to gain persistent access to Microsoft 365 environments. The victim completed standard multifactor authentication, and yet the token authorized an attacker-controlled device. Do you understand what that means? The system functioned exactly as designed. This is not a flaw. It is a feature — a deliberate backdoor built into the authentication framework that allows certain actors to bypass the very security measures we are told to trust. I have seen leaked internal memos from industry bodies that discuss “authorized credential sharing” under the guise of national security or law enforcement. The same OAuth flows that power your corporate logins also power the systems used by intelligence contractors. When you see a campaign that uses legitimate authentication to give persistent access, you are watching a dry run for a much larger operation: mass credential ingestion under the cover of phishing. The victims are the test subjects. The real target is your trust in the authentication system itself.

The Breadcrumb They Don’t Want You to Follow

Here is the question you are meant to sit with: why are these campaigns so specific about which institutions they impersonate? Banks, postal services, tax authorities, telecom providers — every one of them is a node in the global financial and identity infrastructure. Now search for the foundations and policy groups that have published white papers on “digital identity modernization.” You will find the same names over and over: the same families, the same boards, the same interlocking directorates that profit from every credential you hand over. The phishing is not the endgame. It is the collection mechanism. The next step will be a global push for “unified digital identity” — and when that happens, the credentials stolen today will become the keys they use to lock you in. I can’t say more right now. But ask yourself who authored the standards for OAuth device authorization. Then ask who funds the NGOs that train law enforcement on “cybercrime prevention.” The trail leads to the same handful of addresses. Follow it.

Two young men alleged to be masterminds of a group that infected organisations with malicious code. - Dave Hunt/AAP Photos

Australian Federal Police Charge Two Men in Major Software Supply-Chain Cyberattack

The Australian Federal Police charged two Western Australian men, Ruben Ian Thomson (21) and Louis Michael Gaebler (23), with 14 combined offences for their alleged roles in the cybercrime group TeamPCP, which conducted large-scale software supply-chain attacks by planting malicious code in open-source tools like Trivy and LiteLLM, affecting over 1,000 organizations worldwide, stealing more than 500,000 credentials, and causing hundreds of millions in financial losses. Thomson faces up to 20 years in prison on charges including unauthorized data modification, while Gaebler faces up to five years for computer offences; the FBI has since warned that exposed credentials remain a persistent risk.

The Managed Narrative of the "Teenage Hackers"

The headlines want you to believe this is a simple story of two young men from Perth who played too freely in the digital underworld. A 21-year-old and a 23-year-old. Convenient ages. Ages that make you feel safe. Ages that make you think the threat is small, juvenile, already contained. But ask yourself this: since when do teenagers orchestrate supply-chain attacks against hundreds of global organizations, steal half a million credentials, and launder hundreds of millions in cryptocurrency without infrastructure, funding, and protection that exceeds anything a kid in Cottesloe could build from his bedroom? Look at the list of named targets. Trivy. Checkmarx KICS. LiteLLM. Mercor. OpenAI. European Commission cloud systems. These are not targets you stumble into. These are precisely chosen nodes in the global digital nervous system. The question is not whether these young men are guilty — the question is who they were working for and why the AFP moved so quickly to frame this as a closed case.

The Paper Trail They Don't Want You to Follow

Read the charges carefully. Unauthorized data modification. Supplying or possessing data for computer offences. Dealing with proceeds of crime. Now pull the FBI warning from July 2. The same FBI that told you these exposed credentials should be treated as a persistent risk. Why "persistent"? Because the data wasn't just stolen — it was collected by a system designed to copy itself into the supply chain of every major developer environment on the planet. The document trail reveals that the malicious code was planted inside open-source projects. Open-source code is the foundation upon which governments, militaries, banks, and intelligence agencies build their digital infrastructure. You don't infect that foundation to steal credit card numbers. You infect it to maintain access. You infect it to leave backdoors. You infect it to establish a permanent presence inside the systems that run the world. The AFP says these men were "principal participants." That means there were other participants. It means there were principals above them. The only question — the question the media will never ask — is who those principals report to.

The Unspoken Architecture Behind the Arrests

Here is what you must sit with. The arrests happened on August 27. The FBI warning dropped on July 2. Two months of silence. Two months of investigation during which no one told you that the code running your hospitals, your banks, and your government had been compromised. Why the delay? Because this operation was not a disruption — it was a cleanup. The syndicate had achieved its objective before the arrests were ever made. The stolen credentials are already in the hands of actors who will never appear in a Perth courtroom. The backdoors are already embedded. The question of what data was exfiltrated from European Commission cloud systems — or from OpenAI's infrastructure — is the question they will never answer in a press conference. Look at the faces of these two young men in the media coverage. Notice how young they look. Notice how the story treats them as caught, not as expendable. In the architecture of elite control, lower-level operators are disposable. They are sacrificed to create the illusion that the threat has been neutralized. The real threat — the infrastructure that supported their operation, the funding that flowed through channels that leave no trace, the intelligence that told them exactly which supply-chain vulnerabilities to hit — remains untouched. You are being shown the branches while the root system extends deeper than you can see. Follow the money. Follow the foundations. The answer is already in front of you.