Back to all lessons
Awareness Lessons
3 weeks ago

Compromised OAuth Token and Supply Chain Attack Exposes CrowdSec's Private GitHub Repos

The Shai-Hulud attack on CrowdSec illustrates how a single compromised OAuth token — sourced from a former employee's machine via a malicious npm package — can cascade into the theft of 170 private repositories. The failure to revoke OAuth tokens and credentials belonging to offboarded employees created a persistent, exploitable entry point long after the individual left the organization. The TanStack npm supply chain compromise demonstrates how open-source dependencies can silently introduce malicious code that harvests credentials from developer workstations. This matters because stolen source code can expose proprietary logic, embedded secrets, customer data, and vulnerabilities that attackers can weaponize in future campaigns. Organizations that do not treat offboarding and third-party dependency vetting as security-critical processes remain exposed to this class of attack.

Tactical Insight

Immediate actions

  • Audit and revoke all OAuth tokens, API keys, and personal access tokens associated with former employees immediately upon offboarding.
  • Scan all developer workstations and CI/CD pipelines for indicators of compromise linked to the TanStack npm supply chain attack.
  • Rotate all GitHub organization tokens and secrets as a precautionary measure following any confirmed supply chain incident.

Long-term improvements

  • Enforce a formal offboarding checklist that mandates revocation of all third-party OAuth authorizations and SSO access within hours of an employee's departure.
  • Implement a vetted allowlist for approved npm packages and enforce integrity checks (e.g., lock files, provenance attestation) for all open-source dependencies.
  • Adopt short-lived, scoped OAuth tokens with automatic expiry rather than long-lived personal access tokens for repository access.

Detection measures

  • Enable GitHub audit log streaming and alert on anomalous bulk repository cloning or access from unrecognized IP addresses or OAuth apps.
  • Deploy software composition analysis (SCA) tools in CI/CD pipelines to detect newly introduced malicious or typosquatted packages before they reach developer environments.
  • Establish baseline behavioral profiles for repository access patterns and trigger alerts on deviations such as off-hours bulk downloads.