logo

Freelance dev shop Toptal caught serving malware after GitHub account break-in

ID: e47cd88e-ea64-5412-815f-afd597e3f6b5

STIX ID: report--e47cd88e-ea64-5412-815f-afd597e3f6b5

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2025-07-25

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Security researcher Socket discovered that attackers hijacked Toptal's GitHub repositories and injected malicious code into ten npm packages used in the Picasso developer toolbox, enabling GitHub token theft, persistence, and backdoor downloads; Toptal removed the repositories and stated no customers were affected, while Socket recommends token rotation, scanning for malicious lifecycle scripts, and checking dependency logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.