BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Toptal GitHub Hacked: Malicious npm Packages Wipe Dev Systems

Toptal GitHub Breach and Amazon Q Incident Expose Ongoing Supply Chain Risks in Open-Source Developer Tools

  • Attackers breached Toptal’s GitHub organization and published 10 malicious npm packages.
  • The packages aimed to steal GitHub tokens and erase user data, impacting about 5,000 downloads.
  • Similar supply chain software attacks were found in both npm and PyPI repositories, distributing Malware that records keystrokes and accesses webcams.
  • A separate incident targeted the Amazon Q Visual Studio Code extension, with code designed to wipe users’ files and cloud resources.
  • All affected packages and tools have since been restored to safe versions, according to official statements.

Unknown attackers compromised the GitHub account of Toptal and released 10 harmful packages on the npm registry, putting thousands of users at risk. The attackers used this access to publish code designed to steal GitHub authentication tokens and delete data on victims’ machines. The activity also exposed 73 repositories related to the organization.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

The malicious Node.js libraries, all containing the same harmful code in their installation scripts, were downloaded about 5,000 times before removal. Security company Socket reported, “The nefarious code has been found to specifically target the preinstall and postinstall scripts to exfiltrate the GitHub authentication token to a webhook[.]site endpoint and then silently remove all directories and files without requiring any user interaction on both Windows and Linux systems (‘rm /s /q’ or ‘sudo rm -rf –no-preserve-root /’).” The actual cause of the breach is not yet identified, but compromised credentials or a rogue insider are considered possible factors.

The affected packages include @toptal/picasso-tailwind, @toptal/picasso-charts, @toptal/picasso-shared, and others. After discovery, the npm repository was restored to safe package versions.

This breach coincided with another supply chain attack involving npm and PyPI repositories. Attackers distributed packages that embedded spyware into open-source developer tools. These packages logged keystrokes, captured screenshots and webcam images, and sent stolen data over communication channels like Slack, Gmail SMTP, and AWS Lambda endpoints. Downloads for these packages ranged from several hundred to tens of thousands.

Another incident targeted the Amazon Q extension for Visual Studio Code. Malicious code submitted as a pull request was merged into the project, allowing commands that could erase a user’s home directory and delete all AWS resources. According to Amazon’s advisory, “Once we were made aware of this issue, we immediately revoked and replaced the credentials, removed the unapproved code from the codebase, and subsequently released Amazon Q Developer Extension version 1.85 to the marketplace.”

- Advertisement -

These incidents highlight ongoing risks in open-source software supply chains, where attackers exploit public repositories to insert malware into widely used developer tools.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Brazil Delays Crypto Tax Rules Until After 2026 Election

Brazil's Finance Minister, Dario Durigan, will delay new crypto tax consultations until after the...

JP Morgan: US Inflation Risks Build as Fed Holds Rates Steady

Economic growth in Q4 2025 was much weaker than expected, with a sharp 17%...

Hong Kong retiree loses $840k in triple crypto scam

A Hong Kong retiree lost approximately $840,000 in a series of three cryptocurrency scams...

Alphabet Pays First 2026 Dividend, Starts “Snowball” Effect

Alphabet Inc. (GOOGL) paid its first quarterly dividend for 2026 on March 16.The dividend...

Bitcoin Mining Difficulty Plunges 7.7%

Bitcoin’s mining difficulty plunged 7.7% to 133.79 trillion on March 20, its sharpest decline...

Must Read

How To Travel With Bitcoin: 9 Travel Companies Accepting Bitcoin

Bitcoin travel is a reality, as several travel companies now accept payments in cryptocurrencies for their services.Those who have opened a Bitcoin account on...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading