Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data

LowDark Reading · Elizabeth Montalbano·

At a glance

Severity
Low
Used in attacks
No flaws named
Vendors and products
GitHub
Industries
Manufacturing
Reported by
1 outlet

Threat actors stole 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.

We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.

Coverage

One outlet has carried this so far.

  1. Dark ReadingEstablished SourceFirst reported

    2026-09-22 17:32 UTC

Related stories