Tech News
← Home  ·  All topics

Shai Hulud Worm

1 GoKawiil brief on this topic

CrowdSec discloses May breach of 170 private GitHub repos via ex-employee's stolen OAuth token

French security firm CrowdSec disclosed that attackers used the Shai-Hulud worm to compromise a former employee's machine in May, stealing a GitHub OAuth token that still had read access to the company's private repositories. Over roughly nine minutes, attackers downloaded about 170 private repos plus 130+ public ones; CrowdSec only learned of the breach on September 16 after stolen source code surfaced on the cybercrime marketplace pwnforum.