GitHub Security (@GitHubSecurity) on X

X (formerly Twitter) ·

1 min read Original article ↗

GitHub Security on X: "GitHub has uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI. Read more about the impact to GitHub, npm, and our users. https://t.co/eB7IJfJfh1"