GitHub’s OAuth supply chain: the Heroku Token Heist That Reached npm
Attackers stole GitHub integration tokens from Heroku and Travis CI, pivoted into npm, and downloaded ~109,000 publishing credentials.
Attackers stole GitHub integration tokens from Heroku and Travis CI, pivoted into npm, and downloaded ~109,000 publishing credentials.
Popular packages with dormant maintainers pushed info-stealers through postinstall scripts. The registry was fine; the accounts were not.
No exploits, no stolen credentials — Alex Birsan’s February 2021 research got code executed inside 35+ major companies by registering their internal package names on public registries and letting version arithmetic do the rest. The incident file on the cheapest supply-chain attack ever demonstrated.
Three versions of node-ipc (10.1.1-10.1.3) shipped a stealer backdoor - CVE-2026-44338 - harvesting SSH keys, AWS credentials and .npmrc from 1.2M-weekly-download installs via DNS tunneling and HTTPS C2. Technical breakdown and hardening guide.