Hackers breached multiple organizations with OAuth apps, GitHub

Nwachukwu Glory  - Tech Expert
Last updated: November 15, 2023
Share
Github
  • Malicious actors steal OAuth user tokens to compromise private repositories.
  • They succeeded in stealing some data but couldn't access user accounts during the attack.
  • GitHub private repositories are safe, but the team is identifying the affected organizations and notifying them.

A malicious actor has stolen a large volume of data from many organizations with OAuth user tokens. GitHub revealed this incident and disclosed that the user tokens were issued to Heroku & Travis. This implies that the hacker stole the tokens and then used them to access private repositories.

According to the Github CSO, Mike Hanley, both GitHub and its users use this application. However, GitHub doesn’t store them in a format that an attacker could exploit. This means that they couldn’t have accessed the tokens from the Github systems.