Heroku and Travis CI OAuth Tokens Stolen (Apr 2022): Hijacking GitHub Access
Retrospective: this article looks back at events from April 2022, written in 2026 with the benefit of hindsight.
In April 2022, GitHub disclosed that an attacker had used stolen OAuth user tokens issued to two third-party integrators — Heroku and Travis CI — to download data from private repositories belonging to dozens of organizations, including npm.
How it happened
Heroku (owned by Salesforce) and Travis CI both offered GitHub integrations. Users authorized these apps through OAuth, giving them tokens to access repositories. The attacker obtained those tokens — in Heroku's case, after accessing a database containing the tokens — and used them to clone private repositories directly from GitHub. GitHub detected the activity when the attacker used a compromised AWS API key to access npm's infrastructure.
GitHub's own systems were not breached. The tokens were valid; the integrators that held them were the weak point.
Why it mattered
- OAuth tokens held by third parties are as sensitive as passwords — often more, since they bypass MFA.
- Source code repositories contain secrets. Attackers mine cloned repos for cloud keys and credentials.
- CI/CD platforms are high-value targets. They need broad access to code and deployment environments.
Heroku revoked all GitHub OAuth tokens and suspended its GitHub integration for weeks.
Lessons in hindsight
- Review OAuth apps with access to your code repositories and remove unused ones.
- Use short-lived credentials in CI/CD with OIDC federation instead of stored cloud keys.
- Scan repositories for secrets.
- Prefer fine-grained, scoped tokens and GitHub Apps over broad user OAuth tokens.
In hindsight
This incident previewed a broader pattern: SaaS-to-SaaS integrations as an attack path. It recurred in the 2023 CircleCI breach and, at much larger scale, in the 2025 Salesloft Drift campaign against Salesforce tenants.
- How to Secure CI/CD Pipelines With OIDC Federation Instead of Stored Secrets How-To & Hardening
- Detecting Stolen OAuth Tokens: Sentinel and GuardDuty Detections Detection & Response
- CIO Brief: Your Build Pipeline Has the Keys to Production CIO Briefings