Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› GitHub OAuth Token Breach 2022: How Stolen Heroku…
Breach analysis Incident: 15 Apr 2022

GitHub OAuth Token Breach 2022: How Stolen Heroku and Travis CI Tokens Exposed Dozens of Private Repositories

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 8 min read
Category: NHI
On this page

In April 2022, an attacker used stolen OAuth user tokens issued to two trusted integrations, Heroku and Travis CI, to download private GitHub repositories from dozens of organisations, including npm. GitHub detected the campaign on 12 April 2022 when it saw unauthorised access to npm's production infrastructure with a compromised AWS API key. That key, GitHub believes, came from a private npm repository the attacker had cloned with one of the stolen tokens. GitHub said the tokens were not taken from its own systems: they were held by the two integrators, and the attacker used them against the GitHub API exactly as the integrations would. GitHub, Heroku and Travis CI revoked the tokens, and GitHub notified every organisation it found had repositories listed or downloaded.

Key takeaways

  • The attacker never needed a GitHub password. OAuth tokens that users had granted to Heroku and Travis CI apps were stolen from the integrators and replayed against the GitHub API.
  • GitHub says the attacker listed victims' organisations, picked targets, listed their private repositories and cloned some of them, which it called "highly targeted" behaviour.
  • The breach was found because a stolen repository contained a live AWS API key, which the attacker used against npm's production infrastructure.
  • GitHub believed the attacker was mining downloaded repositories for secrets "that could be used to pivot into other infrastructure".
  • The identity lesson: every OAuth grant to a third-party app is a standing credential held by someone else, and it is only as safe as that party's systems.

At a glance

OrganisationsGitHub and npm; Heroku (Salesforce) and Travis CI as the OAuth integrators; dozens of organisations whose private repositories were accessed
WhenDetected 12 April 2022; disclosed by GitHub 15 April 2022; final victim notifications 27 April 2022
AttackerUnattributed
Entry pointOAuth user tokens for the Heroku Dashboard and Travis CI OAuth apps, stolen from the integrators rather than from GitHub
Identities abusedThird-party OAuth user tokens with repository access; an AWS API key found inside a cloned private npm repository
ImpactPrivate repositories listed or downloaded from dozens of organisations; unauthorised access to npm's private repositories and potential access to npm package storage in AWS S3
CategoryNHI. Incident class: confirmed NHI breach (stolen OAuth tokens and a leaked cloud key)

What happened

GitHub's first detection came on 12 April 2022, when it "identified unauthorized access to our npm production infrastructure using a compromised AWS API key." Working backwards, GitHub concluded the key had been obtained "when they downloaded a set of private npm repositories using a stolen OAuth token from one of the two affected third-party OAuth applications." On the evening of 13 April it found the wider theft of third-party tokens and revoked those tied to GitHub and npm's own use of the apps. It told Heroku and Travis CI on 13 and 14 April and published a security alert on 15 April.

The affected integrations were the Heroku Dashboard (Preview and Classic) and Travis CI OAuth apps. GitHub stressed that it did not believe the attacker got the tokens from GitHub, "because the tokens in question are not stored by GitHub in their original, usable formats." With the tokens, the attacker authenticated to the GitHub API, listed each user's organisations, chose targets, listed private repositories and cloned some of them. GitHub said the activity suggested the attackers "may be mining the downloaded private repository contents, to which the stolen OAuth token had access, for secrets that could be used to pivot into other infrastructure."

For npm, GitHub assessed that the attacker downloaded the npm organisation's private repositories and had potential access to npm packages stored in AWS S3, but "did not modify any packages or gain access to any user account data or credentials." Travis CI disputed the impact on its own customers. It said a threat actor had breached a Heroku service and taken a private app OAuth key used to integrate Heroku and Travis CI, and that "we thoroughly investigated this issue and found no evidence of intrusion into a private customer repository," according to BleepingComputer.

GitHub notified victims whose repository contents were downloaded on 18 April, those whose repositories were only listed on 22 April, and sent final notifications on 27 April. It advised organisations to review private repositories for secrets, remove unneeded OAuth apps and check audit logs, tokens, OAuth apps and SSH keys for attacker changes.

Timeline

DateEvent
12 April 2022GitHub detects unauthorised access to npm production infrastructure with a compromised AWS API key.
13 April 2022GitHub discovers the broader theft of Heroku and Travis CI OAuth tokens and revokes those used internally.
15 April 2022GitHub publishes its security alert naming the affected OAuth apps.
18 April 2022GitHub notifies victims whose repository contents were downloaded; Travis CI publishes a bulletin saying customer repositories were not accessed through its key.
22 April 2022GitHub notifies victims whose repositories were listed but not downloaded.
27 April 2022GitHub sends final notifications and publishes its analysis of the attacker's behaviour.

How it happened: the identity attack path

  1. Tokens stolen from the integrators. OAuth user tokens that GitHub users had granted to Heroku and Travis CI apps were stolen from outside GitHub; Travis CI says a Heroku service was breached.
  2. API access as the integration. The attacker authenticated to the GitHub API with those tokens, inheriting whatever repository access each user had granted.
  3. Targeted discovery. The attacker listed organisations, chose targets and listed their private repositories.
  4. Repository theft. Selected private repositories, including npm's, were cloned.
  5. Secrets in stolen code. A cloned npm repository contained a live AWS API key, which the attacker used against npm's production infrastructure, triggering detection.

Impact

  • Victim organisations: dozens of organisations had private repositories listed or downloaded; GitHub notified each one it identified.
  • npm: private repositories downloaded and potential access to packages in AWS S3; GitHub found no evidence packages were modified or user credentials accessed.
  • Downstream risk: any secrets stored in stolen repositories had to be treated as compromised by each victim.

What this means for NHI governance

Two different kinds of non-human identity failed here. The first was the OAuth grant: users had given two popular platforms standing access to their repositories, and those tokens sat in the integrators' systems where the users could not see or protect them. The second was the secret in code: once the attacker had a private repository, an AWS key inside it opened production infrastructure. Neither required phishing a GitHub user.

Third-party OAuth apps are now one of the most common routes in our breach database, from this case to Salesloft Drift and Vercel and Context.ai. Organisations should know which apps hold tokens to their code, with what scopes, and remove those they no longer need. See the SaaS and OAuth App Governance Guide.

Recommendations

  • Inventory OAuth apps with access to your code. Review user and organisation authorisations regularly and revoke anything unused. See the SaaS and OAuth App Governance Guide.
  • Restrict third-party app access at organisation level. Require administrator approval before an OAuth app can access organisation repositories.
  • Keep secrets out of private repositories. A private repository is one stolen token away from public. See our Secrets Management Guide.
  • Monitor API use by integrations. Alert on unusual listing and cloning by OAuth apps, especially across many repositories.
  • Prepare to revoke and rotate fast. Know which secrets each repository holds so they can be rotated when a token is compromised. See the Leaked Credential Response Playbook.

Frequently asked questions

How were GitHub repositories stolen in April 2022?

An attacker used OAuth user tokens stolen from Heroku and Travis CI integrations to call the GitHub API as those apps, list victims' private repositories and clone some of them. GitHub said the tokens were not stolen from GitHub itself.

Was npm affected?

Yes. The attacker downloaded npm's private repositories and used an AWS API key found in them to access npm production infrastructure. GitHub found no evidence that packages were modified or user credentials accessed.

What should organisations using OAuth integrations do?

Review which OAuth apps can access their repositories, remove unneeded ones, require admin approval for new ones, keep secrets out of code, and check audit logs for unusual API activity by integrations.

Salesloft Drift OAuth Breach · Microsoft OAuth Consent Phishing · SaaS and OAuth App Governance Guide · OAuth 2.0 and OpenID Connect Guide · Secrets Management Guide

How NHI Mgmt Group can help

Few organisations can list every third-party app that holds a token to their code or SaaS data. We help teams build that inventory, set approval and review rules, and link each token to an owner. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org