Tech News
← Home  ·  All topics

Crowdsec

2 GoKawiil briefs on this topic

CrowdSec discloses May breach of 170 private GitHub repos via ex-employee's stolen OAuth token

French security firm CrowdSec disclosed that attackers used the Shai-Hulud worm to compromise a former employee's machine in May, stealing a GitHub OAuth token that still had read access to the company's private repositories. Over roughly nine minutes, attackers downloaded about 170 private repos plus 130+ public ones; CrowdSec only learned of the breach on September 16 after stolen source code surfaced on the cybercrime marketplace pwnforum.

CrowdSec confirms private GitHub repositories leaked, no customer data exposed

CrowdSec disclosed that a leak of its private source code repositories occurred in May 2026 and was reported to the company on September 16. The exposed material includes SaaS console code, AWS routines, connectors, and CI/CD tokens, but excludes CrowdSec's public Security Engine software. The company found no evidence of leaked credentials, customer data, or login information, and believes the Tanstack supply-chain compromise was the likely entry point.