CrowdSec, a cybersecurity company specializing in threat intelligence and DDoS mitigation, confirmed that threat actors accessed 170 private GitHub repositories after exploiting a stolen OAuth token belonging to a former employee.

The breach occurred through a supply chain attack targeting TanStack, a popular npm package used by developers worldwide. The attacker, operating under the name Shai-Hulud, obtained the OAuth token from the former employee's compromised computer and used it to access CrowdSec's private code repositories on GitHub.

The OAuth token compromised during the incident granted repository access without requiring additional authentication layers. This allowed the threat actor to enumerate and download sensitive repositories containing source code, configuration details, and potentially authentication credentials embedded in comments or configuration files. CrowdSec stores threat intelligence data, security signatures, and detection methodologies in these repositories, making the breach a serious concern for the company's customers.

TanStack's npm packages, which include widely-used libraries like TanQuery and TanRouter, suffered compromises when their build pipeline was infiltrated. The attacker injected malicious code into packages that developers downloaded millions of times monthly. This supply chain vector proved effective because it targeted developers at infrastructure companies and security firms, not end consumers. CrowdSec developers used TanStack packages in their development environment, exposing them to the initial compromise.

The severity of this incident stems from the cascade effect it demonstrates. A compromised developer dependency led to malware on a single employee's machine, which exposed OAuth credentials, which in turn compromised an entire organization's private source code repository. Each step in this chain represented a failure point that defenders must address.

CrowdSec has not disclosed whether the threat actor exfiltrated the repository data or merely accessed it for reconnaissance. The distinction matters for determining whether source code or configuration secrets now circulate in underground forums or among threat actors. If the actor obtained hardcoded API keys or service credentials, attackers could impersonate CrowdSec infrastructure or access customer accounts.

This incident highlights gaps in OAuth token management practices. Storing long-lived OAuth tokens on developer machines without certificate pinning or IP whitelisting creates risk when laptops are compromised. Many organizations default to generating personal access tokens with broad permissions rather than using time-limited, narrowly-scoped credentials.

Developers using TanStack packages should audit their installation logs and verify no malicious code executed in their environments during the compromise window. Organizations running CrowdSec should review their own access logs to detect any suspicious activity by the threat actor who gained repository access.

The incident also demonstrates why security firms must practice what they preach. CrowdSec sells intrusion detection and threat response tools to enterprises. A breach of this scale affects the company's credibility when advising customers on supply chain security and credential management best practices. The company must now publish a detailed postmortem explaining how it failed to prevent the initial TanStack compromise from spreading laterally into its development infrastructure.