× News Alerts AI News CyberSec News Let's Talk Local AI Bank Tech News Cyber Advisories Contact

Hackers breach Toptal GitHub, publish malicious npm packages

Hackers compromised Toptal's GitHub organization account and used their access to publish ten malicious packages on the Node Package Manager (NPM) index. Security researchers discovered the malicious packages and notified Toptal, which quickly removed the packages from NPM. Toptal is now investigating the incident to determine how the hackers gained access to their GitHub account and to prevent similar incidents in the future.

Hackers breach Toptal GitHub, publish malicious npm packages

Ten malicious packages were uploaded to the Node Package Manager (NPM) index following the infiltration of Toptal's GitHub organization account by hackers, who then exploited this unauthorized access.

Security researchers, upon detecting these harmful packages, promptly informed Toptal, which subsequently purged them from NPM. Toptal is now conducting an investigation into the occurrence, seeking to ascertain the method by which the attackers gained entry to their GitHub account and to implement safeguards to avert comparable incidents in the future.

Subscribe for AI & Cybersecurity news and insights