CrowdSec discloses May breach of 170 private GitHub repos via ex-employee's stolen OAuth token
French security firm CrowdSec disclosed that attackers used the Shai-Hulud worm to compromise a former employee's machine in May, stealing a GitHub OAuth token that still had read access to the company's private repositories. Over roughly nine minutes, attackers downloaded about 170 private repos plus 130+ public ones; CrowdSec only learned of the breach on September 16 after stolen source code surfaced on the cybercrime marketplace pwnforum.
GoKawiil's interpretation of the reporting above, not reported fact.
CrowdSec CEO Philippe Humeau said no infrastructure, databases, or build pipelines were compromised and no source code was tampered with, which limits the immediate damage to exposure rather than sabotage. The incident nonetheless illustrates how a departed employee's lingering access token can become a supply-chain weak point long after they leave, a risk other security vendors may want to audit for in their own credential lifecycle management.
- Attackers used a stolen OAuth token from a former employee's Shai-Hulud-infected machine to access CrowdSec's GitHub.
- About 170 private repositories and 130+ public ones were downloaded in roughly nine minutes on May 22.
- CrowdSec says no infrastructure, databases, or code were altered, and discovered the breach only after leaked data appeared on pwnforum in September.
YubiKey 5C NFC Security Key — This supply-chain attack succeeded because a stolen OAuth token gave persistent access to private repos—exactly the kind of credential theft that hardware security keys help prevent. Using a YubiKey for GitHub and other developer account logins adds a physical authentication factor that malware on a compromised machine can't simply exfiltrate. It's a practical step for any developer or org wanting to harden their GitHub accounts against token and credential theft.
See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: darkreading.com — Elizabeth Montalbano, 2026-09-22
Published there as: “Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.