Waydev disclosed a security incident involving unauthorized GitHub OAuth token use; the company revoked tokens, warned that some repository data may have been cloned, and said personal details such as emails and names may have been exposed, but passwords were not retrieved.
Source