Nuacht

A 'readme' file in the archive states that the threat actor used an exposed GitHub token to access the company's repositories and steal the data.