www.darkreading.com 22 Sept 2026, 17:32 UTC

Shai-Hulud Worm Exposes 170 CrowdSec GitHub Repositories

Shai-Hulud Worm Exposes 170 CrowdSec GitHub Repositories
CyberSIXT Evidence Panel Source marked as original reporting

THREAT actors stole about 170 private GitHub repositories belonging to French security firm CrowdSec after compromising a former employee’s computer with the Shai-Hulud worm. The attackers obtained a GitHub OAuth token that still had permission to read CrowdSec’s private repositories, then downloaded their contents within minutes. CrowdSec said the incident occurred on 22 May 2026, between 05:52 and 06:01 UTC, with the data downloaded from an IP address in Toronto. The company removed the former employee’s account from GitHub on 25 May.

CrowdSec did not discover the breach until 16 September, after an archive containing source code from its GitHub account appeared on the underground marketplace pwnforum. The company said the exposed material included more than 130 public repositories and many private ones, but stated that its infrastructure and databases were not accessed or compromised and that the attackers did not appear to modify source code or build pipelines.

Its investigation, supported by GitHub, linked the activity to a former developer whose computer had been compromised in the TanStack npm supply-chain attack.

CrowdSec said it already used measures including two-factor authentication, privilege separation, password wallets, logging, penetration testing and audits, but did not enforce endpoint detection and response on developers’ machines. It has since introduced endpoint protection focused on malicious packages and extensions.

Security experts cited in the report also stressed promptly removing departing employees’ access, deploying endpoint protection on systems that handle code or infrastructure, and scanning source code for hardcoded secrets.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline