The short version
My GitHub personal access token was exfiltrated — most likely by a supply-chain compromise somewhere in my developer environment. The attacker used it to push malicious commits to several of my private repositories. One of those repositories belonged to a client. The client ended the engagement. They were right to.
That's the...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #3619275