CrowdSec, a French cybersecurity company, has disclosed that attackers copied around 170 of its private GitHub repositories during an attack linked to the Shai-Hulud malware. The incident happened on May 22, 2026, but the stolen source code became public months later in September. According to CrowdSec, the attackers gained access through a GitHub OAuth token belonging to a former employee whose computer had been infected through a compromised TanStack npm package. The token still had permission to access CrowdSec’s private repositories when the attackers used it.

The attack began with the TanStack supply-chain compromise on May 11, 2026, when 42 packages were backdoored with Shai-Hulud, a credential-stealing malware. The malicious package installed on a former CrowdSec employee’s computer allowed attackers to collect sensitive credentials, including a GitHub access token. CrowdSec said the employee had already left the company, but his GitHub access was kept active so he could finish some work. This remaining access later gave the attackers a direct path into CrowdSec’s private code repositories.

On May 22, the stolen GitHub token was used to download the contents of about 170 private repositories within a short period. CrowdSec’s investigation places the activity between 05:52:29 and 06:01:33 UTC, lasting only around nine minutes. The company later removed the former employee’s GitHub access on May 25, three days after the unauthorized repository downloads had already happened. CrowdSec said the stolen repositories mainly contained private source code and internal development material rather than customer production data.

The exposed material included source code connected to CrowdSec’s web console, data-science work, models, automation tools and other internal systems. CrowdSec also said that no customer, user or supplier data was impacted by the incident and that production infrastructure and databases were not accessed. The company found no evidence that attackers changed its source code, build pipelines or infrastructure during the repository theft. However, the incident still exposed proprietary code and highlighted the risk created when old credentials remain active after an employee leaves.

The stolen archive became publicly visible on September 16, 2026, several months after the original repository access took place. CrowdSec was alerted after the source-code archive appeared on an online cybercrime forum and then began investigating the incident in greater detail. The company published its technical analysis in September, confirming that the attack was connected to the earlier TanStack supply-chain compromise. CrowdSec also reported that an exposed AWS credential was tested on August 17, showing that some stolen credentials may have remained useful to attackers after the original repository theft.

The CrowdSec incident shows how a software supply-chain attack can continue creating problems long after the original malicious package has been removed. A compromised developer machine can expose credentials that later provide access to private repositories, cloud services and other company resources. It also highlights the importance of quickly removing GitHub tokens and other access rights when employees leave an organization. Security teams are now expected to review developer credentials, rotate exposed secrets and monitor unusual repository activity to reduce the risk of similar attacks.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news