GitHub today revealed that an attacker is using stolen OAuth user tokens (issued to Heroku and Travis-CI) to download data from private repositories.
See also: GitHub: Automatically blocks commits containing API keys

Since this campaign was first discovered on April 12, 2022, the threat actor has already accessed and stolen data from dozens of victim organizations using OAuth applications hosted by Heroku and Travis-CI, including npm.
"The applications maintained by these integrators were used by GitHub users, including GitHub itself," Mike Hanley, Chief Security Officer (CSO) at GitHub, revealed today.
"We do not believe the attacker obtained these tokens through a breach of GitHub or its systems, because the tokens in question are not stored by GitHub in their original, usable form."
"Our analysis of other behavior by the threat actor suggests that the hackers may be mining the contents of the private repository it downloaded, which was accessed by the stolen OAuth token, for secrets that could be used to spin up other infrastructure."
See also: More security vulnerabilities found by GitHub code scan
According to Hanley, the list of affected OAuth applications includes the following:
- Heroku Dashboard (ID: 145909)
- Heroku Dashboard (ID: 628778)
- Heroku Dashboard – Preview (ID: 313468)
- Heroku Dashboard – Classic (ID: 363831)
- Travis CI (ID: 9216)
GitHub Security detected unauthorized access to GitHub's npm production infrastructure on April 12 after the attacker used a compromised AWS API key.
The attacker likely obtained the API key after downloading several private npm repositories using stolen OAuth tokens.
“Upon discovering the widespread theft of third-party OAuth tokens not stored by GitHub or npm on the afternoon of April 13, we took immediate action to protect GitHub and npm by revoking the tokens associated with GitHub and npm’s internal use of these compromised applications ,” Hanley added.
The impact on the npm organization includes unauthorized access to private GitHub.com repositories and “potential access” to npm packages in AWS S3 storage.
GitHub has contacted Heroku and Travis-CI to ask them to initiate their own security investigations, revoke all OAuth user tokens associated with the affected applications , and begin notifying their own users.

Private GitHub repositories are not affected
While the attacker was able to steal data from the compromised repositories, GitHub believes that none of the packages were modified and no user account data or credentials were accessed in the incident.
“npm uses completely separate infrastructure from GitHub.com. GitHub was not affected in this initial attack,” Hanley said.
“While the investigation is ongoing, we have not found evidence that other private repos owned by GitHub were cloned by the attacker using stolen third-party OAuth tokens.”
GitHub is working to notify all affected users and organizations as additional information is identified.
See also: Microsoft Sentinel: Acquires threat monitoring for GitHub repos
You should review your organization's audit logs and user account security logs for abnormal, potentially malicious activity.
You can find more information about how GitHub responded to protect its users and what customers and organizations should know in the security alert published on Friday.
Information source: bleepingcomputer.com
