A serious security breach hit the Toptalwhen malicious attackers gained access to GitHub organization account and used those privileges to publish malicious packages to the Node Package Manager (NPM) index. The goal was to infect developers’ systems with token-stealing software and crash systems. [Note: See also the company’s official statement on the incident at the end of the article Toptal’s official statement on the incident https://www.toptal.com/#update ]

Toptal is a freelance talent marketplace known for connecting companies with freelancers in fields like software development, design, and finance. The platform uses GitHub and NPM to provide internal developer tools and design systems, such as Picasso.
Malicious code in 10 NPM – 5,000 downloads before removal
The breach occurred on July 20, 2025, when attackers gained access to Toptal's GitHub account and made 73 private repositories public, exposing source code and private projects.
See also: Banana Squad: Malicious GitHub repositories distribute malware
A few days later, they modified the Picasso source code and published ten packages to NPM , with fake versions bearing the official Toptal brand — making them appear to be perfectly legitimate updates.
The malicious packages were the following:
- @toptal/picasso-tailwind (v3.1.0)
- @toptal/picasso-charts (v59.1.4)
- @toptal/picasso-shared (v15.1.0)
- @toptal/picasso-provider (v5.1.1)
- @toptal/picasso-select (v4.2.2)
- @toptal/picasso-quote (v2.1.7)
- @toptal/picasso-forms (v73.3.2)
- @xene/core (v0.4.1)
- @toptal/picasso-utils (v3.2.0)
- @toptal/picasso-typography (v4.1.4)
According to security firm Socket, the packages were downloaded approximately 5,000 times before being detected and removed, potentially infecting many unsuspecting developers.
Package . json files with scripts that stole tokens and deleted systems
The attack was based on the use of malicious preinstall and postinstall scripts within the packages' package.json files.
- The preinstall script stole the GitHub CLI token and sent it to a webhook controlled by the attackers.
- The postinstall script attempted to completely delete the system file with the command sudo rm -rf –no-preserve-root / on Linux (or attempted to delete files recursively and silently on Windows).
This particular technique is particularly destructive, as it can cause total data loss without requiring user interaction.
See also: Water Curse uses GitHub accounts to distribute malware

Toptal has remained silent – the community is worried
Despite the seriousness of the incident, Toptal has not issued a public statement, leaving developers in the dark about what exactly happened and what steps they should take.
The security community is expressing strong concern about the lack of transparency, while Socket confirmed that the company removed the malicious packages on July 23 and reinstated safe versions — but without actively notifying those who may have already installed the dangerous versions.
The method of breach is still unknown
It is currently unclear how the attackers gained access to Toptal's GitHub account. Possibilities being considered include:
- attacks Phishing targeting company developers
- Internal credential leak
- Poor management of access keys or tokens
- Use of unprotected automated bots
See also: GitHub's new Sakura RAT evades AV & EDR protections
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What to do if you used any of the packages
If you are using or recently installed any of the malicious versions, you can do the following:
- Revert to an older, stable version
- Check for leaked GitHub tokens or unusual activity
- Analyzing logs for deletion attempts or strange cron/systemd scripts
- Review your GitHub account permissions and renew tokens
The software supply chain remains a critical target
The Toptal incident highlights the pervasive vulnerability of the supply chain software, particularly in ecosystems like JavaScript/NPM, where dependencies are often numerous and opaque.
Toptal's lack of timely notification heightens concerns about inadequate disaster recovery policies, while highlighting the need for automated dependency analysis and programming security tools.
Toptal points out that the actual scope and impact were much more limited than initially presented.
Toptal's official position on the incident https://www.toptal.com/#update
Toptal, following reports of the incident, clarified that two of its open source projects — Picasso and Xene— were temporarily compromised for a few hours on June 20, 2025, due to a years-old credential leak via LastPass. The attackers gained access after decrypting these old credentials.
According to the company:
- The impact was limited exclusively to the two specific packages, which are hardly used by anyone outside of Toptal.
- There are no known external users, companies, or projects that depend on them.
- The number of "5,000 downloads" mentioned concerns, as the company claims, mainly automated security scanners that downloaded the packages for analysis and not actual users or organizations.
- The malicious code was detected and removed within a few hours, while the webhook used was disabled on July 24. Server logs showed that only 17 unique IP addresses contacted the webhook, a number that Toptal said mainly concerns security tools and not end users.
Toptal also confirmed that:
- No customer, partner or user was affected.
- There was no access or deletion of data from its core systems.
- The affected repositories were immediately restored from clean backups.
The company concludes that it has already implemented additional security measures and continues to monitor all of its open source projects, even those that are no longer used.
Source: www.bleepingcomputer.com
