A mystery hacker is smuggling data out of private code repositories, GitHub warns

An unknown threat actor is harvesting data from private code repositories, with the help of stolen OAuth user tokens issued to Heroku and Travic-CI.

As reported by GitHub, by last Tuesday, the threat actor managed to steal data from “dozens of victims”.

Source