Back Darkreading Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.
An attacker stole 170 private GitHub repositories from the French security firm CrowdSec after compromising a former employee's computer with the Shai-Hulud worm and stealing an OAuth token for his GitHub account.
CrowdSec acknowledged the breach, which happened in May, last week in a blog post outlining the attack and how it happened. Attackers stole a GitHub API token from the former employee's machine that retained permission to read CrowdSec’s private repositories, and then downloaded the contents of those repositories over the course of just several minutes, according to the post.
CrowdSec discovered the breach only on Sept. 16, when a user published an archive containing source code from the CrowdSec GitHub on pwnforum, an underground cybercrime marketplace. The Fuites Info team subsequently contacted CrowdSec the leak, and the company began investigating. Fuites Info shared a post of its own it last week following the company's public disclosure.
Related: ShinyHunters Hacked Cl0p. Now What Cl0p's Victims?
"At that point, we know with a high degree of certainty that the leak is limited to CrowdSecurity’s source code, including 130+ public repositories and many private ones," CrowdSec CEO Philippe Humeau wrote in the post, adding that none of CrowdSec's infrastructure or databases had been accessed or compromised. The attackers don't appear to have altered CrowdSec's source code for their own purposes either, "whether in the open source software, our private source code, or the build pipelines," he wrote.
A 9-Minute Cyberattack Showcases Supply Chain Risk
CrowdSec traced the attack as occurring on May 22, between 5:52 am and 6:01 am UTC, when one of the founders of BreachForum and a member who goes by the online name "diencracked" downloaded the GitHub repository data from an IP address in Toronto.
The company's investigation eventually led them to a URL that contained a GitHub OAuth token , which investigators realized had been used to obtain access to the private repositories. However, that token no longer existed in its own GitHub audit records, so CrowdSec enlisted the help of GitHub to determine how the access happened.
Eventually, investigators traced the attacker's repository operations back to the account that had performed them, identifying that it belonged to the former CrowdSec developer "who had just left the company, but that was still part of the GitHub organization for legitimate reasons, and his account was used to dump the repositories," Humeau wrote.
"The ex-employee got compromised by the TanStack supply chain attack , matching the methodology," he wrote. The company removed the account from GitHub on May 25, three days after the incident.
Related: Cybercriminals Are Hiding New Malware in Torrents for Popular Films
Denis Calderone, co-founder and chief operating officer at Suzu Labs, says the incident could have been avoided with basic security hygiene.
"Revoking access the moment someone leaves is as fundamental as security gets," he says. "It's day-one stuff. CrowdSec didn't do it. They kept a departed employee's GitHub access open so he could wrap up some outstanding work, and that lingering account is what attackers used to clone 170 private repositories."
CrowdSec did not immediately return a request for . But Humeau noted in the blog post that CrowdSec already had numerous security mechanisms in place, including but not limited to: strict privilege separation, two-factor authentication, password wallets, and extensive logging, pen testing, and audits.
Other Key Takeaways for Defenders
If a company as locked-down as CrowdSec can get breached by a supply chain attack via one basic security faux pas, it certainly puts a typical organization at an even greater risk of a breach, observes John Strand, owner of security firm Black Hills Information Security. "The obvious question is how many other companies have been compromised that don’t have that same level of security rigor?" he tells Dark Reading.
Related: Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
One protection that CrowdSec lacked at the time of the incident was endpoint detection and response (EDR) , which was not enforced on developers' machines, Humeau acknowledged.
"We've since started using endpoint protection that actively focuses on malicious packages, extensions, etc.," he wrote. "As supply chain attacks become the new plague and virtually anyone can get caught in them, we should have done this earlier."
Indeed, in addition to making sure organizations shut down accounts of any employees the day they are out of the door, putting "EDR on any workstation that touches code or infrastructure" is a good practice to follow when it comes to poisoned package attacks because "that developer laptop is part of your attack surface now ," Calderone says.
Organizations also should treat their own source code as sensitive data to protect it from similar attacks, Calderone adds. "Scan it for hardcoded secrets before an attacker does," he advises, "and assume anything ever committed to it is one bad day from being public."
Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician.
Want more Dark Reading stories in your Google results?
The State of Cloud Security: The Latest Challenges
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Essential News & Insights from Black Hat USA 2025
Effective Alert Triage: Reducing Noise and Finding Real Threats
Effective Alert Triage: Reducing Noise and Finding Real Threats
Cybersecurity Outlook 2027
Cybersecurity Outlook 2027
Threat Exposure Analytics: Measuring and Communicating Security Risk
Threat Exposure Analytics: Measuring and Communicating Security Risk
Benchmark Scores Are a False Flag
Benchmark Scores Are a False Flag
Building an Effective Red Team: Beyond Penetration Testing
Building an Effective Red Team: Beyond Penetration Testing
Operation DoppelBrand: Weaponizing Fortune 500 Brands
CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks
Deja Vu: Salesforce Customers Hacked Again, Via Gainsight
Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
