Heroku has now revealed that stolen GitHub integration OAuth tokens from last month led to the breach of an internal customer database.

The cloud platform owned by Salesforce acknowledged that the same compromised token was used by attackers to exploit ' hashed and salted passwords from "a database."
Heroku explains forced password reset
This week, Heroku began performing forced password resets for a subset of user accounts following security incident , without fully explaining why.
On Tuesday night, some Heroku users received an email titled “Heroku security notification – resetting user account passwords on May 4, 2022,” informing users that their account passwords were being reset in response to the security incident. The reset would also invalidate all API access tokens and require users to generate new ones, the email explained.
GitHub detected the activity on April 12, 2022, and notified Salesforce on April 13, 2022, at which time Horeku began its investigation.
However, the initial security incident reported involved threat actors stealing OAuth tokens issued for Heroku and Travis-CI and abusing them to download data from private GitHub repositories owned by dozens of organizations, including npm.
See also: NHS: Employees' email accounts hacked and sent phishing messages
These tokens were previously used by Travis-CI and Heroku OAuth applications to integrate with GitHub for application development.
By stealing these OAuth tokens, threat actors were able to access and download data from GitHub repositories owned by those who authorized the compromised Heroku or Travis CI OAuth applications with their accounts. Note that infrastructure, systems , or private repositories themselves were not affected by the incident.
However, this still didn't explain why Heroku would need to reset certain user account passwords.
It turns out that the compromised token for a Heroku machine account obtained by threat actors also allowed unauthorized access to Heroku's internal customer account database:
"Our investigation revealed that the same compromised token was used to gain access to a database and compromise hashed and salted passwords for customer user accounts," Heroku explains in an updated security advisory.
“For this reason, Salesforce is ensuring that all Heroku user passwords have been reset and potentially affected credentials are refreshed. We have rotated internal Heroku credentials and implemented additional detections. We continue to investigate the source of the token breach.”

See also: F5: Critical BIG-IP RCE bug allows device takeover
A YCombinator Hacker News reader claimed that the “database” he is referring to may be what was once called “core-db.”.
The reader in question appears to be Craig Kerstiens of PostgreSQL platform CrunchyData, who has previously worked with Heroku.
“The latest report refers to ‘a database’ which is probably the internal database,” the reader says.
“I don’t want to speculate too much, but it appears that [the attacker] had access to internal systems. There should be more clarity on what exactly happened.”
Heroku users are advised to continue to monitor the security alerts page for updates related to the incident.
Information source: bleepingcomputer.com

