Skip to main content
Back to overview
Medium

Toptal's GitHub Account Breached, Malicious npm Packages Published

Hackers compromised Toptal's GitHub organization account, gaining access to 73 repositories and publishing 10 malicious npm packages.

Key points

  • Toptal's GitHub organization account was breached.
  • 73 repositories were exposed, and 10 malicious npm packages were published.
  • Malicious packages aimed to steal GitHub authentication tokens and wipe systems.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Confidentiality impact

Threat source not confirmed

03

Potential impact

Potential data exposure

Confidentiality

Published
Jul 23, 2025
Updated
Jun 26, 2026
Confidence
Medium
Evidence
1 source

Structured assessment

Signal analysis

It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch exposure paths that could affect data, operations or third-party trust.

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

ToptalData DisclosureToptalMaliciousPackages Published HackersGitHubThese

Quick context

Questions about this signal

What happened in this signal?

Hackers compromised Toptal's GitHub organization account, gaining access to 73 repositories and publishing 10 malicious npm packages. These packages were designed to steal GitHub authentication tokens and potentially wipe victim systems. The compromise was detected on July 20, 2025, and publicly reported on July 23, 2025. Toptal subsequently deprecated the malicious packages and reverted to safe versions.

When was this signal reported?

Shadow Tier lists Jul 23, 2025 as the signal date.

Which organization is connected to this signal?

Toptal is the organization connected to this public signal.

Explore Toptal