Security alert: Attack campaign involving stolen OAuth user tokens issued to two third-party integrators
On April 12, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including npm. Read on to learn more about the impact to GitHub, npm, and our users.
Discussion around the web
- Hacker News281 · 67 💬
Score breakdown
- Technical depth70
- Practical value60
- Originality85
- Writing quality82
- Source reputation85
- Recency0
- External engagement34
- On-site engagement0
More like this
Slack Engineering53
Streamlining Security Investigations with Agents
Dominic Marks·unknown·9 min read
The Cloudflare Blog52
Thanksgiving 2023 security incident
unknown·20 min read
The GitHub Blog57
Disrupting supply chain attacks on npm and GitHub Actions
Greg Ose, Zachary Steindler·unknown·15 min read
The GitHub Blog57
Introducing fine-grained personal access tokens for GitHub
Hirsch Singhal·unknown·13 min read
Engradar shows a summary and links to the original article. The full article is hosted on github.blog.