Back to Feed
BreachesSep 22, 2026

Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data

Shai-Hulud attack steals 170 private GitHub repos from CrowdSec via compromised OAuth token.

Summary

The Shai-Hulud threat actor has compromised CrowdSec's GitHub repositories, stealing 170 private repositories. The attackers exploited a compromised OAuth token, which was obtained from a former employee's computer. This access was facilitated by the TanStack npm supply chain attack, highlighting the risks associated with open-source dependencies.

Indicators of Compromise

  • malware — Shai-Hulud

Entities

Shai-Hulud (threat_actor)CrowdSec (vendor)GitHub (product)OAuth (technology)npm (technology)