Tech
GitHub says the attacker used stolen OAuth user tokens issued to Heroku and Travis-CI to download data from private repositories belonging to npm and other organizations (Sergiu Gatlan/BleepingComputer)
Sergiu Gatlan / BleepingComputer:
GitHub says attackers used stolen OAuth user tokens issued to Heroku and Travis-CI to download data from private repositories belonging to npm and other organizations– GitHub revealed today that attackers are using stolen user tokens (issued to Heroku and Travis-CI OAuth) to download data from private repositories.
Source link