> Using their initial foothold of OAuth user tokens for GitHub.com, the actor was able to exfiltrate a set of private npm repositories, some of which included secrets such as AWS access keys.
> Using one of these AWS access keys, the actor was able to gain access to npm’s AWS infrastructure.
How many individual best practices were not followed to result in this nightmare? Sigh.