CrowdSec's GitHub Data Stolen in Shai-Hulud Supply Chain Attack
Cybersecurity firm CrowdSec has confirmed that threat actors accessed and stole 170 of its private GitHub repositories. The breach was tied to the Shai-Hulud campaign, a supply chain attack that spread through the TanStack npm package ecosystem.
According to reports, the attackers gained access using an OAuth token that had been stolen from a former employee's computer. This allowed them to authenticate as a trusted user and pull private code without needing to breach CrowdSec's systems directly.
This incident highlights a growing pattern in supply chain attacks: compromising developer tools and credentials, such as npm packages and OAuth tokens, to reach otherwise well defended organisations. Even security vendors are not immune when third party dependencies or leftover access credentials are involved.