← Toptal

2025 Toptal — GitHub org compromise; malicious npm packages from Picasso/Xene supply chain

2025 Unknown records affected Share on X

Data compromised

Primarily developer/GitHub CLI tokens and repository integrity in disclosed narratives—not a retail customer PII dump

Technical writeup

Industry reporting and Toptal’s public follow-ups described unauthorized access to Toptal’s GitHub organization traced to long-lived credentials (press narratives frequently linked the entry path to recycled secrets from an older LastPass-era leak). Attackers briefly flipped many private repositories to public, tampered with open-source packages Picasso and Xene, and published malicious npm builds aimed at harvesting developer tokens and destructive scripts. Toptal maintained that customer, partner, and external end-user databases were not the target of the activity and that npm download counts reflected scanners more than production adoption.

Root cause

Compromised developer/GitHub credentials enabling org takeover and package supply-chain tampering

References