The GitHub Blog·unknown·15 min read·Mike Hanley59

Security alert: Attack campaign involving stolen OAuth user tokens issued to two third-party integrators

On April 12, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including npm. Read on to learn more about the impact to GitHub, npm, and our users.

Discussion around the web

Score breakdown

  • Technical depth70
  • Practical value60
  • Originality85
  • Writing quality82
  • Source reputation85
  • Recency0
  • External engagement34
  • On-site engagement0

More like this

Engradar shows a summary and links to the original article. The full article is hosted on github.blog.