1
Published signals
currently linked to this company
Company intelligence
toptal.com
This company page brings together public reporting currently associated with Toptal. It reflects signals published by Shadow Tier and should not be read as a complete incident history.
Company links
1
currently linked to this company
0
recent published signals
0
recent published signals
0
confidence classifications
June 26, 2026
most recent published signal
Company signals
Hackers compromised Toptal's GitHub organization account, gaining access to 73 repositories and publishing 10 malicious npm packages. These packages were designed to steal GitHub authentication tokens and potentially wipe victim systems. The compromise was detected on July 20, 2025, and publicly reported on July 23, 2025. Toptal subsequently deprecated the malicious packages and reverted to safe versions.
FAQ
It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Toptal.
No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.
The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.