GitHub has uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI. Read more about the impact to GitHub, npm, and our users. github.blog/2022-04-15-sec…
15
661
976
0
132
April 22, 2022 update: As of 7:33 PM UTC on April 22, 2022, GitHub has notified victims of this campaign whom we have identified as having repository details listed using stolen OAuth app tokens, but did NOT have repository contents downloaded. github.blog/2022-04-15-sec…