Stolen OAuth User Tokens used in Data Breach

Stolen OAuth User Tokens used in Data Breach

GitHub has investigated a security incident that uncovered abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including npm.…