A Departed Employee’s Token Quietly Opened 170 Private Security Repositories
An employee can leave while their machine identity remains alive. CrowdSec says an OAuth token associated with a former employee’s laptop was used to clone roughly 170 private repositories. GitHub later traced the token’s lifecycle to the TanStack supply-chain incident that began months earlier.
The company’s final incident report says the cloning occurred on 22 May. The access exposed source code and some secrets embedded in repositories. CrowdSec says its production infrastructure and databases were not accessed, no code or build pipeline was changed, and the incident did not expose client or partner data beyond limited contact information held in code.
The repository was the target, not the deployment pipeline
That boundary matters. Stealing private source is serious, but it is not the same as pushing malicious code to customers. CrowdSec says the actor did not alter repositories, packages or builds. The investigation identified 83 monitoring email addresses and 51 potential investor contacts in the accessed material. One AWS SNS token was still valid, but it was narrowly scoped. The company reports that a probe against it was observed.
Most other secrets were already unusable, according to CrowdSec. That is reassuring only in a limited sense. The incident still demonstrates that an old workstation token could outlive the employment relationship and provide a broad map of private code, integrations and security logic.
GitHub connected the access to the TanStack chain
CrowdSec’s account places the event downstream of the May TanStack compromise. BlackTree has already covered the wider TeamPCP supply-chain activity. This is a separate victim reconstruction: it shows how a token captured through one ecosystem incident can remain useful long after the first public alarm.
The important control failure was not simply that a token existed. It was that ownership, device status and token revocation were not continuously reconciled. An offboarding checklist may remove an employee from payroll and interactive login while delegated application credentials continue to work.
Offboarding must include machine identities
- Revoke delegated tokens at departure. Include OAuth applications, personal access tokens, SSH keys, signing keys and automation credentials.
- Inventory authorised applications. Record which third-party integrations can read private repositories and which user or device granted the access.
- Shorten token life. Prefer expiring credentials and reauthorisation over indefinite access.
- Alert on bulk cloning. Repository access from a new device, geography or dormant identity deserves immediate review.
- Scan the stolen scope. Treat secrets found in cloned repositories as exposed until their validity and downstream access are checked.
- Separate code theft from code tampering. Preserve evidence about both, and report only what the investigation supports.
The strategic lesson is that the identity perimeter includes credentials held by tools and old devices. A user account can be closed correctly while its delegated access remains a working route into the organisation’s most sensitive engineering material.
Sources
- CrowdSec, final TanStack supply-chain attack analysis, published 18 September 2026. No publication time was provided.
- BlackTree, existing TeamPCP coverage, published 27 August 2026.


