Getty Images
CrowdSec breach exposes security blind spots in developer access
Disabling corporate logins isn't enough. The CrowdSec breach demonstrates how offboarding oversights create quiet, long-term backdoors.
A recent incident at cybersecurity firm CrowdSec highlights a dangerous blind spot in modern identity management: disabling a corporate email account does not guarantee a developer's access is actually gone.
When a departing CrowdSec engineer requested extra time on GitHub to wrap up loose ends, IT granted the extension -- a routine favor in software engineering. The former engineer's personal laptop was later compromised by malicious TanStack NPM packages that carried the Shai-Hulud malware, which harvested developer credentials and tokens. An attacker then used the compromised GitHub access to download private CrowdSec repositories.
The security company only discovered the breach after nearly four months, when its stolen source code surfaced on a public forum.
The incident underscores a fundamental flaw in enterprise access control. While IT teams often treat offboarding as an administrative process -- disable the account, collect the laptop, close the ticket -- developer access lives in a fragmented ecosystem of personal access tokens, SSH keys and third-party SaaS platforms.
When temporary exceptions are granted without platform-enforced expiry, offboarding ceases to be a security control and becomes a persistent liability.
"The biggest risk is the exception nobody writes down," Jen Waltz, founder of Imajenative, a Chicago-based IT and cybersecurity services firm, told TechTarget Cybersecurity. "CrowdSec had already removed this person's other access but kept his GitHub account active so he could finish some work. That is not an unusual favor. In engineering, it is the most common one. Offboarding gets treated as a date on a calendar when it is actually a state that persists until every credential is accounted for."
The exception is the problem
What happened at CrowdSec illustrates how easily developer workflows escape standard identity governance.
Shutting down an employee's company account doesn't necessarily revoke that person's permissions across every system. Centralized single sign-on (SSO) deactivation rarely reaches deep into developer ecosystems. Engineers routinely generate persistent access tokens, SSH keys and OAuth grants tied to third-party repositories -- credentials that remain valid long after corporate identity providers mark an employee as offboarded.
"Revoke at the token layer, not the account layer," recommends Waltz. "Explicitly kill active sessions, personal access tokens, OAuth grants, SSH keys and deploy keys, then rotate any shared secret that person could have read. Treat account removal as the last step, not the only one."
When operational needs force an extension, security teams must govern the exception with hard controls rather than informal trust.
"Put the 'let him finish some work' exception on a timer," Waltz said. "The business reason is usually legitimate, so do not fight it. Bound it instead. Time-limited access with a platform-enforced expiration date, scoped to the specific repositories, read-only wherever possible, logged, with a named owner. If the extension isn't documented with an end date, it doesn't exist."
The threat can linger
Even when access is finally revoked, the risk profile remains elevated long after the employee departs. Security teams must also account for credentials that may have been exposed before anyone knew there was a problem. There's also the possibility that evidence of that exposure might not surface for months.
"Access management isn't just an IT housekeeping task; it's a critical security control that directly impacts supply chain integrity," said Elvia Finalle, senior cybersecurity analyst at Omdia. "Former employee access represents a ticking time bomb."
That kind of delay makes audit logs and continuous monitoring critical, Waltz said. Organizations should retain development-platform logs long enough to investigate activity that might not be discovered until well after the initial compromise, while monitoring for activity from terminated identities and known credentials.
To mitigate lingering credential risk, Finalle recommends five baseline controls:
- Automate offboarding: Revoke at least 90% of access within hours of termination, rather than relying on manual processes.
- Continuously validate access: Ensure active credentials belong only to current employees.
- Use time-limited credentials: Make credentials expire automatically instead of depending on someone to revoke them.
- Monitor credential activity: Detect use of leftover credentials as quickly as possible.
- Audit access regularly: Identify and close gaps in access management.
For many CISOs, the scope of the problem remains hidden until they look backward. Finalle notes that auditing former employee access over a two-year window almost always yields alarming -- and motivating -- results.
Craig Galbraith is the founder and owner of Galbraith Multimedia, an independent journalism company that provides writing, editing, video hosting, podcasting, onstage presentation and consulting services to the technology industry.