logo

Hackers breach Toptal GitHub account, publish malicious npm packages

ID: c691a4ed-90a0-5245-9f9e-cd5e163f77b7

STIX ID: report--c691a4ed-90a0-5245-9f9e-cd5e163f77b7

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2025-07-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Hackers hijacked Toptal's GitHub organization and published ten malicious NPM packages and modified Picasso package source that included a preinstall script to steal CLI GitHub authentication tokens and a postinstall script to attempt filesystem wipes; private repositories were briefly made public. The malicious packages were available for a short period and reportedly downloaded thousands of times, though Toptal later stated most downloads were automated scanners and that only a limited number of unique IPs contacted the attacker's webhook, concluding no known impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.