CrowdSec breach exposes security blind spots in developer access | TechTarget

https://www.techtarget.com/rms/onlineimages/check_g496816315.jpg

A recent incident at cybersecurity firm CrowdSec highlights a dangerous blind spot in modern identity management: disabling a corporate email account does not guarantee a developer's access is actually gone.

When a departing CrowdSec engineer requested extra time on GitHub to wrap up loose ends, IT granted the extension -- a routine favor in software engineering. The former engineer's personal laptop was later compromised by malicious TanStack NPM packages that carried the Shai-Hulud malware, which harvested developer credentials and tokens. An attacker then used the compromised GitHub access to download private CrowdSec repositories.

The security company only discovered the breach after nearly four months, when its stolen source code surfaced on a public forum.

The incident underscores a fundamental flaw in enterprise access control. While IT teams often treat offboarding as an administrative process -- disable the account, collect the laptop, close the ticket -- developer access lives in a...

Copyright of this story solely belongs to www.techtarget.com. To see the full text click HERE

Read more