Incident Response
GitHub OAuth Token Theft: The Heroku and Travis CI Breach
Attackers stole OAuth tokens from Heroku and Travis CI to access private GitHub repositories across dozens of organizations, including npm itself. The full scope of the breach took weeks to unravel.
Apr 15, 20225 min read