2025 Toptal — GitHub org compromise; malicious npm packages from Picasso/Xene supply chain
Data compromised
Primarily developer/GitHub CLI tokens and repository integrity in disclosed narratives—not a retail customer PII dump
Technical writeup
Industry reporting and Toptal’s public follow-ups described unauthorized access to Toptal’s GitHub organization traced to long-lived credentials (press narratives frequently linked the entry path to recycled secrets from an older LastPass-era leak). Attackers briefly flipped many private repositories to public, tampered with open-source packages Picasso and Xene, and published malicious npm builds aimed at harvesting developer tokens and destructive scripts. Toptal maintained that customer, partner, and external end-user databases were not the target of the activity and that npm download counts reflected scanners more than production adoption.
Root cause
Compromised developer/GitHub credentials enabling org takeover and package supply-chain tampering