Investigating unauthorized access to GitHub-owned repositories
GitHub reported that an unauthorized actor used a compromised personal access token to clone private repositories owned by GitHub itself. The intrusion did not involve GitHub's core production systems, and the affected repositories were forks used for planning purposes. GitHub is rotating credentials and investigating.