Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data
LowDark Reading · Elizabeth Montalbano·
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Vendors and products
- GitHub
- Industries
- Manufacturing
- Reported by
- 1 outlet
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.
Read the full story at darkreading.com ↗Established Source
We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.
Coverage
One outlet has carried this so far.
2026-09-22 17:32 UTC
Related stories
- Hackers start exploiting critical WordPress flaw for code execution
BleepingComputer · 2026-09-23
- Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
The Hacker News · 2026-09-23
- Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
BleepingComputer · 2026-09-23
- Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
The Hacker News · 2026-09-23
- Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
The Hacker News · 2026-09-23 · exploited