ThreatPaper

#github-oauth-token

2 cases

Mandiant documents an intrusion where an AI coding assistant recommended attacker-poisoned software; a developer accepted it, and the attacker used the live session to steal GitHub OAuth tokens and spread the Shai-Hulud worm across ~100 internal repos. How the session was taken over is undisclosed.

Supply Chain AttackAI & Machine LearningMalware

The TanStack npm compromise (CVE-2026-45321) stole a former CrowdSec employee's retained GitHub token, used on May 22 to clone ~170 private repos. CrowdSec's Sept 17 statement said no personal data leaked; its Sept 18 report disclosed 83 user emails and 51 investors' details.

Supply Chain AttackData Breach