Toptal’s GitHub Organization Hijacked: 10 Malicious Packages...
Blog post from Socket
In July 2025, Toptal's GitHub organization was compromised, leading to the publication of at least 10 npm packages containing malicious payloads that aimed to exfiltrate GitHub authentication tokens and destroy victim systems. The breach, discovered by Socket's Threat Research Team, involved the public exposure of 73 repositories, with the malicious packages accumulating around 5,000 downloads before being detected and removed. The attack leveraged npm lifecycle hooks to execute a two-stage assault involving token exfiltration and system destruction, affecting both Unix and Windows systems. Possible vectors for the compromise include phishing campaigns, insider threats, credential compromise, or a targeted supply chain attack, although the exact method remains unclear. Toptal responded rapidly to mitigate the damage by deprecating the malicious package versions and reverting to stable ones. This incident highlights the evolving threat landscape of supply chain attacks, urging organizations to adopt robust security measures such as two-factor authentication, regular credential rotation, and monitoring for unusual repository activities to safeguard against similar threats.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.