Security alert: Attack campaign involving stolen OAuth user tokens issued to two third-party integrators | The GitHub Blog
github.blog · Aug 16, 2022
On April 12, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including npm. Read on to learn more about the impact to GitHub, npm, and our users.