Correction to this thread: I said the developer secrets were stolen from environment variables but actually it looks
like they stole a JWT token that was hard-coded in source code. More of my notes here:
Developer JWT Token Theft from Hardcoded Source Code
By
–